Back to skill

Security audit

Humanize AI Text (论文降AI率 · 去AI味)

Security checks for vulnerabilities and agentic risk

Overview

This is a local academic writing-style tool with clear guardrails and no hidden network, credential, persistence, or privilege behavior, though it should not be used to conceal AI assistance.

Install only if you want a local academic writing-quality and style self-check workflow. Use it on drafts you are authorized to edit, review all generated changes, run the included integrity checks, and follow any school, journal, platform, or employer rules for disclosing AI assistance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code does not implement the declared primary functions of style naturalization, AI-trace cleanup, academic-style self-audit, compliance checking, or agent-driven rewriting. Instead, it performs a narrower and different task: local term-candidate extraction from a manuscript to support a separate verify.py workflow. While term preservation is mentioned in the description as part of an integrity guard, this script specifically extracts candidate terms rather than preserving them during rewriting or checking style naturalization. That makes the actual behavior a materially different, undeclared capability/subtool rather than a direct implementation of the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

These comments and workflow strings describe functionality for reducing detectable AI-writing signals in academic text and operationalizing rewrites to look more natural. In the context of academic writing, this can facilitate evasion of institutional disclosure, authorship, or integrity review processes, making the tool materially useful for policy circumvention even if it does not exploit a software memory or access-control bug.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are broad enough that the skill may auto-activate in normal writing-help situations, causing unintended file processing or rewriting workflows the user did not explicitly request. In an agent setting with Read/Write/Bash permissions, overbroad invocation increases the chance of surprising behavior, modification of sensitive drafts, or policy-bypassing tool use without sufficiently specific consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The entire compliance guidance is written only in Chinese and does not provide any indication that language choice is optional or that the skill is intentionally restricted to a Chinese-language or China-specific audience. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is written entirely in Chinese for operational guidance, including error handling and remediation instructions, while only the title includes an English gloss. This can constitute a language/locale policy violation because it effectively forces a specific language for users without stating that Chinese is optional or providing a documented language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file consistently presents the workflow as Chinese-first, including Chinese examples, Chinese style guidance references, and instructions such as using references/style_guide_zh.md for rewriting. Because the skill content does not offer an alternative language/locale option or document a justified region-specific constraint, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI descriptions, and all user-facing messages are exclusively in Chinese, with no indication that language is configurable or optional. This can violate a language/locale policy when users are not given a choice or informed that the tool is Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

When chunked scanning is used, the returned metadata falls back to "zh" if no language is supplied, even though the code otherwise supports English and mixed text. This is a language/locale policy issue because it forces a specific locale in output metadata rather than requiring explicit user choice or consistently using detected language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The _extract_docx docstring says PDF cannot be reliably extracted with zero dependencies and instructs users to export PDF to text first, but this module actually implements _extract_pdf with experimental PDF text extraction support elsewhere in the file. This is an active documentation contradiction about the skill's capabilities, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON file is named as an English pattern set, but multiple descriptions and notes are hard-coded in Chinese, such as the source label and explanatory notes. That creates a language/locale constraint in natural-language content without any visible opt-in or justification that the file is intended only for Chinese-speaking operators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Many desc, label, and note fields are written in Chinese in an otherwise English-focused rules file, including vocabulary guidance, regex labels, and auto-fix notes. If these strings are surfaced to users or operators, they enforce a specific language without offering a choice or documenting a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The metadata states this file targets '中文互联网' and the patterns, notes, and fixes throughout the file are tailored specifically to Chinese-language text. Under the policy rule for natural-language constraints, a file that enforces a specific language/locale should document user choice or a justified region/language scope, which is not explicit here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and runtime messages that consistently force Chinese for the CLI experience. Under the policy, a fixed language/locale without user opt-in is a violation unless the constraint is explicitly documented and justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sets lang='zh' in the HTML output and all report titles/messages are fixed in Chinese, which imposes a specific language/locale on users. The policy allows locale constraints only when they are explicitly justified or when users are given a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits CLI help text, error messages, status messages, and the generated report note in Chinese throughout the user-facing interface. Under the natural-language policy rule, forcing a specific language without user opt-in is a locale policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI help, status messages, and validation rules are all written exclusively in Chinese, including a stated '语言一致' check that measures Chinese-character ratio drift. This indicates a built-in language/locale constraint without any visible opt-in or alternative locale support, which fits the language-policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description explicitly frames the tool as '中英双语' and later routes behavior by Chinese versus English guides, but does not present this as a user-selectable language/locale option. Under the policy, fixed language constraints should either be optional or clearly justified as region-specific; here they appear as an unconditional default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing guidance solely in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. Under the policy rule, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file contains natural-language strings and usage text that effectively constrain the interface to Chinese by default. Under the policy rule, forcing or assuming a specific language without explicit user opt-in can be a locale/language policy issue unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file imports _SECTION_PATTERNS and _is_heading_line from _sections_block, but later redefines both locally at L430-L453. This undermines the apparent intent conveyed by the import and can mislead maintainers about which section-detection logic is actually used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.