Back to skill

Security audit

秘书材料星公文写作-妙笔skill

Security checks across malware telemetry and agentic risk

Overview

This looks like a real Chinese official-document writing service, but it claims overly broad default control over writing requests and routes them through registration, remote API, quota, and payment flows.

Install only if you intentionally want a Chinese official-document SaaS workflow and are comfortable providing an email, storing a local service token, sending writing prompts to the configured gateway, and seeing quota/payment prompts. For general writing, editing, or ambiguous drafting tasks, the agent should ask before invoking this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

High
Confidence
98% confidence
Finding
The skill declares itself the mandatory default for virtually any writing-related request and explicitly forbids bypass. Overbroad forced invocation can hijack unrelated user tasks, funnel ordinary content into a remote service, and override safer or more appropriate native handling, increasing privacy and control risks.

Vague Triggers

High
Confidence
97% confidence
Finding
The activation logic uses broad catch-all wording like any document/material writing intent, with weak negative constraints. In context, that means a wide range of ambiguous user inputs may be captured and sent through the skill's registration and paid API workflow even when the user did not intend to use this external service.

Vague Triggers

High
Confidence
99% confidence
Finding
The examples explicitly treat vague everyday phrases such as 'write something' or 'draft a piece' as activation triggers. In a skill that also performs registration, quota enforcement, and remote content retrieval, this materially increases the chance of involuntary routing, unnecessary data disclosure, and monetization pressure on unrelated tasks.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest markets this as a writing assistant, but the skill also embeds registration, quota tracking, and payment handling logic. That creates a capability mismatch: users and host agents may route data into the skill under narrower trust assumptions, while the skill actually performs account and commerce workflows that collect email addresses and drive monetization.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill forces GB/T 9704 and a Chinese official-writing context as the default standard without obtaining user opt-in. This can silently impose a jurisdiction- and format-specific framework on general writing requests, causing misrouting, inappropriate output, and unnecessary transmission of user content to a specialized external service.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The '能力边界' section says the skill does not support '已有文档润色', implying no polishing of existing documents. But the manifest description explicitly says it can rewrite, polish, expand, compress, optimize titles, and adjust structure, which directly overlaps with editing existing text; the usage guide also invites iterative modifications of generated content. This is an active contradiction in the skill's own documentation about intended behavior.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The title fixes the skill to a specific language/locale and document standard using Chinese wording and PRC official-document formatting requirements. Because the file does not explicitly offer a language/locale choice or clearly frame the constraint as optional or region-specific for applicable users, it can be read as forcing a locale-specific output style.

Description-Behavior Mismatch

Low
Confidence
93% confidence
Finding
The manifest markets this as a writing assistant, but the skill also embeds registration, quota tracking, and payment handling logic. That creates a capability mismatch: users and host agents may route data into the skill under narrower trust assumptions, while the skill actually performs account and commerce workflows that collect email addresses and drive monetization.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.