Back to skill

Security audit

novel-writing

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language novel-writing helper that manages local project files, with a file-import option users should invoke carefully.

Install this only if you want a Chinese-language local novel-writing workflow. Treat the --file option as sensitive: it can read any local path the agent can access and save that content into the novel project, so only provide paths to intended draft files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and top-level documentation are written entirely in Chinese and present the skill as a general-purpose novel-writing tool, with no indication that language output is optional or limited to a China-specific use case. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the style guide entirely in Chinese, including headings and instructions, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The write command accepts a user-supplied --file path and reads arbitrary local files without constraining the path to the novel workspace or to approved import locations. In an agent setting, this expands the skill from novel authoring into local file access, which can expose sensitive data such as keys, configs, or unrelated documents if a prompt or workflow causes the agent to pass attacker-chosen paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that force a specific language/locale experience for all users. The skill does not provide an opt-in choice or indicate that it is intentionally limited to a Chinese-speaking context, which fits the stated language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.