Back to skill

Security audit

电商运营决策台

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed e-commerce analysis toolkit that runs local calculators, compliance checks, dry-run previews, and report generation without hidden platform access or destructive actions.

Before installing, treat this as a Chinese-language e-commerce operations toolkit. Provide only the store exports or business data needed for the specific analysis, review generated reports before using them for business decisions, and keep actual price changes, publishing, deletion, account login, and platform actions under human control. Ensure the runtime has a writable output/temp directory if PDF generation is needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Even if only a single profit/ROI or stocking-related script exists, the skill text instructs users to rely on a much broader validated workflow. That overstatement can mislead downstream agents and users into over-trusting outputs, especially where the skill claims expert review, dry-run safety, and compliance checks that may not exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if only a single profit/ROI or stocking-related script exists, the skill text instructs users to rely on a much broader validated workflow. That overstatement can mislead downstream agents and users into over-trusting outputs, especially where the skill claims expert review, dry-run safety, and compliance checks that may not exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if only a single profit/ROI or stocking-related script exists, the skill text instructs users to rely on a much broader validated workflow. That overstatement can mislead downstream agents and users into over-trusting outputs, especially where the skill claims expert review, dry-run safety, and compliance checks that may not exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Even if only a single profit/ROI or stocking-related script exists, the skill text instructs users to rely on a much broader validated workflow. That overstatement can mislead downstream agents and users into over-trusting outputs, especially where the skill claims expert review, dry-run safety, and compliance checks that may not exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Even if only a single profit/ROI or stocking-related script exists, the skill text instructs users to rely on a much broader validated workflow. That overstatement can mislead downstream agents and users into over-trusting outputs, especially where the skill claims expert review, dry-run safety, and compliance checks that may not exist.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
| **批量改价/上下架预演(dry-run)** | `batch_plan.py` | `--data plan.json --csv-out preview.csv` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
| **批量改价/上下架预演(dry-run)** | `batch_plan.py` | `--data plan.json --csv-out preview.csv` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
| **批量改价/上下架预演(dry-run)** | `batch_plan.py` | `--data plan.json --csv-out preview.csv` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
| **批量改价/上下架预演(dry-run)** | `batch_plan.py` | `--data plan.json --csv-out preview.csv` |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README is written entirely in Chinese and presents the skill as-is without offering any language or locale choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and references shell execution, file reads/writes, and environment access, but does not declare any explicit tool scope or permissions boundary. In an agent setting, this can lead to over-broad runtime authority, making it easier for the skill to access local data or execute commands beyond what is necessary for its business function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON contains natural-language policy content exclusively in Chinese, including source attribution and all forbidden-word guidance, but does not document that the skill is China-specific or that users can opt into this locale. Under the language/locale policy rule, forcing a specific language without user opt-in or explicit justified scoping can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains end-user guidance exclusively in Chinese, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file contains user-facing policy/instruction content exclusively in Chinese, and there is no statement that the skill is region-specific or that users may choose another language. Under the natural-language policy rule, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill specification is written as a fixed Chinese-only operating protocol, including required output artifacts and prompt templates, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is written as a prescriptive handbook for all consumer-facing copy and states that any such copy produced by the skill must go through this process before delivery. The instructions throughout require specific Chinese-language stylistic patterns and do not offer any user opt-in or alternative language/locale path, which is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file specifies the skill's instructions and templates exclusively in Chinese, which can effectively force a specific language on users. The policy says to flag language or locale constraints when the skill does not offer user opt-in or explain why the locale restriction is necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file presents all instructions and guidance exclusively in Chinese, and there is no natural-language indication that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing guidance solely in Chinese and does not mention any language preference, localization setting, or regional scope. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance explicitly instructs the skill to use '亲和中文' when asking users for missing data, which imposes a specific language on users. This is a natural-language locale policy issue because the file does not offer any alternative language option or user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions, CLI help context, and status messages that assume Chinese as the only operating language. Per the policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains user-facing natural language in the module docstring and later CLI messages that assume Chinese as the only supported language. The policy forbids forcing a specific language or locale unless the skill offers opt-in or clearly documents a justified locale restriction, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The argparse description, help text, error text, and rendered diagnostic output are all fixed to Chinese, which enforces a language choice on all users. There is no mechanism for locale selection or documented justification for restricting the tool to Chinese-language use.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI description, decision labels, and rendered output are all hard-coded in Chinese, indicating the skill is designed to operate only in that language. For an all-file-types language policy check, this is a locale constraint without user opt-in or an explicit documented justification that the tool is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.