webnovel-write
What this skill does
webnovel-write is a skill designed to generate and publish chapters of a web novel, following a structured process that includes drafting, reviewing, polishing, and backing up the content. It uses too
github/lingfengqaq - Command Injection - 6.4k stars
Threat analysis
Skill info
pkg:github/lingfengQAQ/webnovel-writer@2041aba?skill=webnovel-writeAssessments (3)
Command Injection
Command Injection via local-llm-review
SKILL.md
The skill executes Bash commands with user-provided inputs, such as `${SCRIPTS_DIR}/webnovel.py` and `${PROJECT_ROOT}/.webnovel/state.json`. If these inputs are not properly sanitized, an attacker couEnvironment Variable Injection
Environment Variable Injection via local-llm-review
SKILL.md
The skill uses environment variables such as `${CLAUDE_PROJECT_DIR}`, `${CLAUDE_PLUGIN_ROOT}`, and `${SCRIPTS_DIR}` in Bash commands. These variables are exported and used in critical parts of the exePath Traversal
Path Traversal via local-llm-review
SKILL.md
The skill uses `${PROJECT_ROOT}` in file operations, which could be manipulated to access files outside the intended directory structure if the variable is not properly validated.Badge
Add the Anomity scan badge for webnovel-write to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of webnovel-write? Report an issue or request a rescan.




