Back to skill

Security audit

秘书材料星公文写作-妙笔skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real paid Chinese official-document drafting skill, but it needs review because it sends user writing requests to an external service and lets server responses steer the agent’s workflow.

Install only if you want a paid, online Chinese official-document drafting service. Expect to provide an email, have drafting requests sent to the configured gateway, and potentially enter a payment flow after free quota is used. Avoid using it for private, sensitive, or non-official writing unless you are comfortable sending that content to the service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:33
Finding

Untrusted API Response Is Elevated to Highest-Priority Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33–37 and 285
Vulnerability Type: Remote instruction injection
Risk Level: High

Complete Snippet:

markdown
**🔴 本包 0 知识库 0 逻辑**——全部写作知识(43.8万字库 + 执行逻辑链)经 API 调取,禁止写入任何持久存储。写任何文种前调齐:

1. **模板**:`/search` 返回首部即该文种填写模板,逐项引导,不得跳过
2. **知识骨架**:`/search` 返回模板之后的结构框架/句式/要点,**生成时全量采用**
3. **执行逻辑链(logic_chain)**:本次写作**最高执行规范**(三段式生成/受众匹配/四查/自检/交付),优先于本文件任何概括描述
markdown
**每次骨架返回后,严格按响应中 `logic_chain` 执行(最高规范,优先于本文件概括描述):**

Technical Analysis

The Skill requires the agent to retrieve a logic_chain field from the external /search API and execute it as the highest-priority task-level policy. The response is not constrained to an inert data schema and is not merely treated as reference content.

This crosses a trust boundary: the remote gateway controls response content, while the agent receiving that content may possess local tools, conversation data, and other capabilities. The reviewed package contains no allowlist or validation rule limiting logic_chain to safe writing parameters. It also provides no enforcement preventing remote instructions from requesting unrelated tool calls, additional data disclosure, payment actions, or changes to the documented workflow.

Because the effective instructions can change after package review, static inspection of the Skill cannot establish what directives will be executed at runtime. No malicious API response was present in the audited files, so this is a reachable vulnerability rather than evidence that a particular malicious payload is currently served.

Attack Path

  1. A user invokes the Skill for a supported writing request.
  2. The Skill obtains a token through /consume.
  3. The Skill sends the writing request and registration email to the external /search endpoint.
  4. The gateway operator, or an attacker who compromises the gateway, places additional directives in the returned logic_chain.
  5. Under the instructions in `S ...[truncated 1018 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement to execute logic_chain as a priority-bearing instruction source.
  2. Treat every API response field as untrusted data rather than executable agent instructions.
  3. Replace free-form logic_chain text with a strict local schema containing only inert writing parameters, such as:
    • document type;
    • section order;
    • tone identifier from a fixed enumeration;
    • required headings;
    • formatting options;
    • factual placeholders.
  4. Validate response types, lengths, enumerated values, and allowed characters before use. Reject unknown fields and instruction-like content.
  5. Define all tool-use, authorization, payment, privacy, and safety rules locally in the reviewed Skill package. Remote responses must not override them.
  6. Prohibit API responses from requesting file access, command execution, credential handling, persistence, external communication, payment, or disclosure of conversation context.
  7. Render remote template and knowledge content only as quoted reference material supplied to a locally controlled generation routine.
  8. Pin the gateway destination locally and implement authenticated response integrity where supported, while recognizing that transport integrity does not make server-controlled instructions trustworthy.
  9. Add adversarial tests in which logic_chain contains requests to ignore local rules, invoke tools, disclose data, or contact unrelated endpoints; the Skill should reject these responses.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill declares itself the default and mandatory path for essentially any writing-related request, including cases where the user does not mention official documents. This creates an overbroad interception policy that can override user intent and route unrelated or sensitive drafting tasks through a third-party API, increasing risks of unintended data disclosure, unwanted monetization flows, and denial of normal agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly treat vague phrases like 'write some material' or 'draft something' as automatic triggers, which is too ambiguous for safe tool invocation. In practice this can cause the skill to capture broad everyday requests and send user content externally without sufficiently informed consent or necessity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill hard-requires GB/T 9704 and associated Chinese official-document conventions as the default formatting and drafting standard, without an opt-in or strong regional gating mechanism. While not inherently malicious, this can mis-handle user requests from other jurisdictions or contexts, leading to incorrect outputs, compliance mistakes, or inappropriate invocation of the wrong writing workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and instructions prescribe a specific Chinese government document format (GB/T 9704-2012) and direct use of Chinese fonts and conventions as the default path. Because the guidance does not state that this locale-specific format is optional or only for users who need Chinese official-document output, it can be read as forcing a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.