Back to skill

Security audit

Humanizer-Text AI写作痕迹去除

Security checks for vulnerabilities and agentic risk

Overview

This is a simple text-rewriting skill with no code execution, credentials, persistence, or hidden data access found.

Use this skill when you explicitly want text rewritten to sound less AI-generated. Review the result for factual accuracy, source preservation, and unintended language or tone changes before publishing or submitting it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase "Or invoke directly when editing documents" does not specify what exact trigger phrase, command, or context should activate the skill. Because it lacks constraints or negative examples, it creates ambiguity about when the skill should run versus when ordinary document editing should not invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill body is written entirely in Chinese and presents the behavior as a fixed-language experience, without indicating that the output should follow the user's language. In a mixed-language environment, this can lead to unintended language switching, user confusion, and unsafe routing where content is transformed into the wrong language or loses fidelity during rewriting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance is extremely broad: users are told to send any AI-generated text and receive a rewritten version. That can overlap with ordinary writing/editing requests and cause the skill to trigger in situations where the user did not explicitly ask for AI-humanization, increasing the chance of unintended transformation of content or bypass of higher-level review flows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.