Vague Triggers
- Category
- Not specified by scanner
- Confidence
- 89% confidence
- Finding
技能描述覆盖“文生视频、图生视频、动作控制、单镜头/多镜头视频、状态请求”等大量常见视频生成场景,触发范围较宽,容易与其他媒体生成或任务查询类技能发生重叠。误触发后,代理可能在错误上下文中引导用户进入特定供应商工作流,导致错误工具选择、混淆确认流程,或把本应由其他技能处理的请求错误路由到该技能。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Kling AI media-generation plugin that discloses its remote OAuth MCP use and requires user confirmation before credit-consuming or state-changing actions.
Install this only if you intend to connect OpenClaw to Kling AI. It may upload your selected media to Kling, query your Kling account/credits, and consume Kling credits after you explicitly confirm a generation request; non-Chinese users should take extra care that all consent and billing prompts are understood.
技能描述覆盖“文生视频、图生视频、动作控制、单镜头/多镜头视频、状态请求”等大量常见视频生成场景,触发范围较宽,容易与其他媒体生成或任务查询类技能发生重叠。误触发后,代理可能在错误上下文中引导用户进入特定供应商工作流,导致错误工具选择、混淆确认流程,或把本应由其他技能处理的请求错误路由到该技能。
L03 的自然语言描述整体以中文限定技能使用方式,文件中也未说明可根据用户语言偏好切换输出语言。按规则,若技能隐含或明示强制特定语言而没有用户选择或合理的区域性说明,属于语言/locale 政策风险。
The file title and the entire contract are written in Chinese, and there is no accompanying statement that language choice is user-selectable or limited to a justified region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.
This file contains user-facing instructional content only in Chinese, which can force a specific language experience on users without opt-in. The policy requires flagging language or locale constraints unless the skill offers a choice or clearly justifies the restriction.
The entire skill guidance is written only in Chinese and provides no indication that language selection is optional or user-driven. Under the locale policy, forcing a specific language without user opt-in is a natural-language policy concern unless the regional constraint is clearly documented and justified.
The manifest description and the entire skill guidance are written as prescriptive Chinese-language instructions, with no indication that the skill can operate in other languages or adapt to the user's locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
The skill content is written entirely in Chinese and does not provide any opt-in or fallback for users interacting in other languages. This can cause the agent to respond in a language the user did not request, leading to misunderstandings around confirmation, billing/credit consumption, authorization, and task execution in a workflow that can trigger paid external actions.
This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language. Under the policy for natural-language violations, forcing a specific language without user opt-in is in scope.
This markdown file is written entirely in Chinese and does not indicate that language selection is optional or limited to a specific regional/compliance context. Under the policy rule for language/locale constraints, forcing a single language without opt-in is a natural-language policy violation.
The entire troubleshooting document is written in Chinese and does not indicate that language selection is optional or limited to a China-specific deployment. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.
The entire skill reference is written in Chinese and does not indicate that language selection is optional or user-driven. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is documented and justified.
The entire workflow is written only in Chinese and provides no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.
No suspicious patterns detected.