Back to skill

Security audit

雄韬创作锚 - 创作就怕没有灵感

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese content-creation framework skill with some rigid style and scoping caveats, but I found no hidden data access, persistence, exfiltration, or destructive behavior.

Install only if you want a strongly styled Chinese content framework. Use explicit prompts when you do not want the persona, language, poster/PDF generation, or visible rationale, and only run file-generation modes when you are comfortable creating local output files with the required tools.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad content-generation skill that automatically builds structured content frameworks for any topic and supports multiple thematic modes and output formats. The supplied code does not perform any of that logic. Instead, it is a narrow utility script that renders a specific local HTML file to a PNG image using Playwright. While image output is mentioned in the description, this code alone only implements that one rendering step and lacks the core claimed functionality, making the description materially inaccurate relative to the provided code chunk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

这是一个 markdown 技能说明文件,适用 SQP-1。L003 将技能适用范围表述为“任何话题”,但没有限定任务类型、输入范围或不适用场景,也没有给出负例,属于触发条件过宽的描述,容易与普通创作求助重叠。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 适用于所有文件类型。L220 明确写明“所有产出必须遵守此语气规范”,随后强制要求固定的中文江湖化表达和第一人称人格口吻;该文件未说明用户可选择其他语言或表达风格,属于未获用户选择的语言/locale 约束。

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly requires the model to reveal a 'thought process' block before every response. Exposing internal reasoning is dangerous because it can leak hidden decision criteria, increase prompt-injection susceptibility, and disclose information about internal policies or guardrail behavior that an attacker can use to optimize bypass attempts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation framing is extremely broad: 'any topic thrown in' implies the skill may engage on ordinary user requests without clear invocation boundaries. Over-broad triggers can cause unintended skill takeover, overriding user intent or applying this framework in contexts where it is inappropriate, which is a prompt-routing and policy-compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill imposes a mandatory persona, vocabulary blacklist, and stylistic constraints on all outputs without user opt-in. A forced style can conflict with user instructions, accessibility needs, enterprise tone requirements, or safety messaging, and may suppress clearer wording in favor of a rigid persona, making the skill less controllable and more prone to instruction conflicts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default mode trigger is ambiguous because it activates on 'default' conditions without a precise rule for when no mode is specified. This can lead to unexpected behavior, where normal conversation is silently reformatted into the skill's outline mode, reducing user control and increasing the chance of instruction collision with higher-priority system or user requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document states that titles carry the weight and motion of Chinese calligraphy and frames this as a defining requirement of the style. Because the file does not indicate that this language/locale-specific choice is optional or justified by a region-specific purpose, it presents a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly sets lang="zh-CN", and all visible content is written in Chinese, which imposes a specific language/locale on users. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific; neither is indicated here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L249-L253 declare an absolute prohibition on specific words, including “复盘”. Later, the document itself uses “复盘” in the chess path chain at L223 and again as a required step in output/workflow language, so the documentation's stated constraint contradicts the actual prescribed content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.