Back to skill

Security audit

AI大模型专家|AI漫剧动态漫画制作工厂

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language workflow guide for turning stories into AI comic/drama production plans, with no hidden code or unsafe installation behavior found.

Before installing, consider that this skill is aimed at Chinese-language AI comic/drama production and may call AI-HIVE media-generation tools; review model costs and approve paid or bulk generation tasks explicitly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The default prompt uses a broad request pattern ('请把我的小说、剧本或创意转换成...') that could match a wide range of ordinary creative-assistance requests. The file does not provide limiting conditions, explicit trigger phrases, or exclusions to clarify when this skill should activate versus more general writing or media-generation skills.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
All user-facing metadata and the default prompt are written exclusively in Chinese, with no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Static analysis

No suspicious patterns detected.