Back to skill

Security audit

Novel Generator Skip

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese long-form fiction workflow that writes local story files and memory notes, with no evidence of hidden network access, credential use, or malicious behavior.

Install only if you want a Chinese serialized-novel workflow that writes markdown files locally. Use it in a dedicated project directory, review output/ and .learnings/ before reusing the workspace, and avoid --clean unless you are comfortable deleting prior generated chapter files and resetting story memory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/init-novel.sh (reported line 78)May include surrounding context.

sh
if [ "$CLEAN" = true ]; then
    log_step "清除旧的输出文件..."
    rm -rf "$OUTPUT_DIR"/*.md 2>/dev/null || true

    log_step "重置记忆文件..."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The initialization example includes ./scripts/init-novel.sh 我的小说名 --clean without explaining what --clean deletes or resets. A destructive flag presented as the default example can cause users or agents to remove prior outputs or state unintentionally, which is especially risky in automated environments where commands may be copied verbatim.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description includes broad English activation phrases such as 'write a novel', 'generate fiction', and 'create stories', which can match many ordinary writing requests and cause the skill to be invoked when the user did not specifically ask for this workflow. Because the skill requires file read/write access and persistent memory behavior, over-triggering expands the chance of unintended filesystem modifications and inappropriate context capture.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The metadata specifies 'language: zh-CN', and the surrounding instructions are written as if the skill operates in Chinese by default. This can be a language/locale policy issue when the skill forces a specific language without an explicit opt-in, alternative language support, or a documented reason for the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs use of an initialization script that clears prior .learnings/ records, but it does not present a prominent warning, confirmation step, or backup guidance. In a skill with persistent memory and file write permissions, this creates a real risk of accidental data loss, including deletion of prior story state or other user-authored records stored in that workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file title and instructions are entirely in Chinese and direct the system to automatically expand user input into a completed prompt template, implying a fixed language/locale for the skill's output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all guidance exclusively in Chinese, starting from the title and continuing throughout the document. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The --clean path performs irreversible deletion of existing chapter outputs and overwrites all learning/memory files with template content without any confirmation, backup, or dry-run behavior. In an agent-integrated workflow, a mistaken flag, misunderstood user request, or automation bug can destroy accumulated novel state and prior work, causing significant integrity and availability loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README presents the skill as a Chinese-language novel generator and the examples and instructions are all in Chinese, which may imply a fixed language/locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or choice is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that each chapter is output as an independent markdown file and that memory files are automatically maintained, but it does not clearly warn users that using the skill will create and modify files in the workspace. In an agent-skill context, implicit file writes can surprise users, especially when run in repositories or shared workspaces, leading to unintended changes or polluted state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's headings and instructional content are entirely in Chinese, including the title and all template sections, with no indication that language selection is optional. Under the policy for natural-language violations, a skill artifact that imposes a specific language without user opt-in can violate language or locale requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown guide is entirely written in Chinese and presents its instructions as the default behavior, with no indication that other languages are supported or that the user may choose their preferred language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing comments, help text, status messages, and workflow instructions are presented only in Chinese. This imposes a fixed language choice on users without opt-in or an explicit statement that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.