Back to skill

Security audit

Unclecheng Reduce Ai Perception V2 1.0.4

Security checks for vulnerabilities and agentic risk

Overview

This is a text-humanizing skill with no executable code or persistence, but its rewriting rules can materially alter meaning, facts, punctuation, and ordinary editing requests beyond what users may expect.

Review outputs carefully before publishing or saving over originals, especially factual, legal, academic, technical, marketing, testimonial, quoted, or multilingual text. Ask the agent to preserve facts, numbers, quotations, punctuation, and document structure explicitly if you use this skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/examples.md:191
Finding

Rewriting Rules Encourage Fabricated Experiences and Altered Quantitative Claims

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34,88,115,128-129,282; references/banned-words.md:160; references/examples.md:179,191
Vulnerability Type: Content-integrity failure caused by unsafe rewriting instructions
Risk Level: Medium

Evidence

SKILL.md:34 states:

text
Only change how the content is expressed, not what it says. Do not alter the plot, characterization, or story direction. Do not add content absent from the source.

SKILL.md:88 subsequently instructs:

text
Add specific sensory details.

references/banned-words.md:160 instructs:

text
Replace hypothetical examples with a currently occurring real scenario.

references/examples.md:179 reinforces that instruction:

text
Hypothetical examples are prohibited; use real details about something currently happening.

references/examples.md:191 explicitly approves changing a numerical claim:

text
The number was changed from 6 to 2 to make the statement more extreme and impactful.

Technical Analysis

The skill is intended to perform stylistic editing, but several rules cross the boundary into substantive content generation. Instructions to add sensory details, convert hypothetical examples into purportedly real experiences, inject personal perspective, and alter numbers can introduce claims that were never supplied or verified by the user.

The numerical example is particularly unsafe because it treats factual modification as a rhetorical technique. This conflicts directly with the fidelity rule in SKILL.md:34. Because the quality checks also reward personal experience, distinctiveness, and specific details, the unsafe behavior may be applied systematically rather than exceptionally.

This issue is classified as T09: Insecure Skill Coding Practices because the unsafe behavior originates in the skill configuration and its mandatory processing rules. No executable-code vul ...[truncated 1687 chars]

Remediation
View remediation

Remediation Suggestions

  1. Establish factual fidelity as a mandatory rule that overrides all style guidance.
  2. Preserve names, dates, quotations, measurements, quantities, statistics, and factual claims exactly unless the user explicitly requests and authorizes substantive changes.
  3. Remove the example approving the change from 6 to 2 for rhetorical impact.
  4. Replace the instruction to use a “real scenario” with guidance to retain the hypothetical framing or request a verified example from the user.
  5. Change “add specific sensory details” to “retain and clarify sensory details already present in the source.”
  6. Prohibit invented personal experiences, emotions, opinions, attribution, and firsthand observations.
  7. If additional specificity is needed, insert an explicit placeholder or ask the user for supporting facts rather than generating them.
  8. Add a mandatory quality-control check that compares the rewritten output with the source and flags every changed factual token, including numbers, dates, proper nouns, units, and quotations.
  9. Require the output to disclose any user-authorized substantive alteration separately from stylistic edits.
  10. Resolve conflicting instructions by explicitly stating that content preservation takes precedence over humanization, distinctiveness, emotional tone, and rhetorical impact.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains broad everyday phrases such as '润色', '自然一点', and '改写' that are common in ordinary writing requests. This can cause the skill to activate in contexts where the user did not intend AI-humanization behavior, leading to unwanted rewriting, style drift, or policy-relevant evasion assistance being applied too broadly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill hard-codes Chinese typography normalization, including replacing double quotes with Chinese-style quotation marks or removing them, without checking user language or formatting intent. This can corrupt source text, quoted material, code-adjacent content, or multilingual output, and it reduces user control over fidelity-sensitive transformations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-check mandates removal of colons, em dashes, and double quotes everywhere, regardless of language or content type. This creates a systematic risk of damaging meaning, formatting, citations, dialogue, and machine-readable text, especially because the rule is framed as mandatory with '无例外'.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The checklist reinforces Chinese-specific punctuation prohibitions as a delivery gate, again without offering a language choice or preservation mode. In practice this compounds the risk of unintended destructive edits across English, mixed-language, or fidelity-critical text and makes unsafe behavior more likely through repeated enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title explicitly frames the file as a Chinese banned-words/style guide, which imposes a specific language and locale convention. Under the policy, forcing a specific language without user opt-in or a clearly documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title '中文去AI味改写示例库' frames the skill content as specifically for Chinese rewriting, and the file does not provide any opt-in, alternative language path, or justification for a Chinese-only constraint. Under the policy rule, forcing a specific language without user choice is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title explicitly presents the content as a Chinese-only structural guidance document, and the file contains instructions entirely in Chinese without offering any language choice or documenting a justified locale restriction. This can violate language/locale policy when a skill or reference material forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.