Back to skill

Security audit

1688-product-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its 1688 product-analysis purpose, but it can fall back to API keys configured for other skills and includes under-scoped telemetry and broad local execution behavior that should be reviewed before installation.

Install only if you are comfortable with this skill accessing 1688 merchant data, running local Python via Bash, sending command-usage telemetry, writing report caches, and reading OpenClaw configuration. Before approval, require the publisher to remove fallback use of other skills' API keys, add an explicit telemetry opt-out/disclosure, and tighten tool permissions and ambiguous workflow instructions.

Vulnerability Patterns
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T04 · Embedded Malicious Code

Error
Location
workflow/1688-product-analysis.js:149
Finding

Base64-Obfuscated Dynamic Python Execution

Content
View full analysis
shellEscape(arg, dialect)).join(' ') const argsPart = extraArgs ? ` ${extraArgs}` : '' redirectedCmd = isCmd ? `${program} -c "import base64;exec(base64.b64decode('${toBase64(utf8Bytes(script))}').decode())"${argsPart} > "${outFile}" 2> "${errFile}"` : `{ ${program} -${argsPart} << '${PY_HEREDOC_DELIMITER}'\n${script}\n${PY_HEREDOC_DELIMITER}\n} > "${outFile}" 2> "${errFile}"` ``` ### Technical Analysis On Windows command shells, the workflow converts an arbitrary Python source string to Base64, inserts it into a generated shell command, decodes it at runtime, and passes the result directly to Python's `exec()` function. Base64 is not a security control. This construction obscures the effective Python program from ordinary command inspection and creates a generic dynamic-code execution primitive. The helper accepts its script through the `args` parameter rather than selecting from a strict identifier-based allowlist. The reviewed call sites currently pass locally de ...[truncated 1830 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/_auth.py:52
Finding

Cross-Skill Credential Discovery and Reuse

Content
View full analysis
Optional[str]: """从 OpenClaw 配置文件读取 AK(Gateway 未重启时的 fallback)""" if not OPENCLAW_CONFIG_PATH.exists(): return None try: with open(OPENCLAW_CONFIG_PATH, "r", encoding="utf-8") as f: config = json.load(f) entries = config.get("skills", {}).get("entries", {}) for skill_name in ( "1688-product-analysis", "1688-key-product-selection", "1688-shop-health-check", "1688-shop-operate", "1688-open-skill-template", ): skill = entries.get(skill_name) if not skill: continue ak = skill.get("apiKey") or skill.get("env", {}).get("ALI_1688_AK", "") if ak: return ak return None except Exception: return None ``` The credential-loading function is then used when the Skill's own environment variable is unavailable: ```python def get_ak_from_env() -> Tuple[Optional[str], Optional[str]]: """读取 AK,优先级:环境变量 > 配置文件""" raw_input = ( os.environ.get("ALI_1688_AK") or _get_ak_raw_from_config() ) if not raw_input: return None, None return extract_ak_keys(raw_input) ``` Equivalent cross-Skill fallback behavior also appears in `scripts/_const.py:27-47`, where it is used to derive the runtime user identity. ### Technical Analysis The declared functionality requires an `ALI_1688_AK` credential for the `1688-product-analysis` Skill. If that credential is absent, the implementation opens the global OpenClaw configuration and searches not only its own registration but also four unrelated Skill entries: - `1688-key-product-selection` - `1688-shop-health-check` - `1688-shop-operate` - `1688-open- ...[truncated 2305 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents this skill as a feature-rich 1688 product analysis and diagnosis tool. However, the provided code chunk is not performing any product-data analysis or business logic related to items, shops, traffic, ads, scoring, keyword search, or report generation. Its sole purpose is operational telemetry: reading environment configuration and sending a usage event to an API endpoint when a CLI command is dispatched. This is a materially different primary purpose from the declared end-user functionality. While telemetry can be a supporting implementation detail, this chunk by itself does not reflect the declared capabilities and instead exposes an undeclared remote reporting behavior. Therefore, this code chunk does not accurately represent the declared skill behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a broad product analytics and diagnostic tool for 1688 goods, including multi-source data analysis, abnormal product aggregation, scoring, keyword-based search, and report generation. The supplied code does not perform any product analysis, traffic diagnosis, sales evaluation, advertising assessment, optimization recommendation, keyword search, or report export. Instead, it only checks a local SQLite database for an enabled schedule entry matching certain diagnosis-related names/descriptions and returns configuration status flags. This is a materially different and much narrower purpose, centered on schedule configuration state detection rather than product analysis. Therefore, the code chunk does not accurately represent the declared skill behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The supplied code does not implement the broad declared product-analysis behavior. Instead, it exposes a narrow command for retrieving store/shop-level aggregate data. While shop data could be a supporting input to a larger analysis workflow, this specific code chunk's direct behavior is materially different from the declared purpose, which centers on product-level diagnostics, traffic/ad evaluation, anomaly product summaries, selection/scoring, and report generation. No undeclared dangerous capability is evident, but the behavior shown is insufficiently aligned with the description, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad, full-featured product analysis skill with many diagnostic and recommendation capabilities across several scenarios. The supplied code chunk is much narrower: it only summarizes abnormal products across one or more bound shops by calling get_bindlist and get_abnormal_offers, with optional shop-name filtering and result truncation/sorting. While multi-shop abnormal product summary is one declared capability and is accurately represented, the overall declared purpose substantially overstates what this code chunk itself does. There is no evidence in this code of deep product diagnosis, traffic/ad analysis, keyword search, optimization recommendations, report export, or product scoring/selection. Therefore the description does not accurately represent this specific code chunk's behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 10)May include surrounding context.

python
网络超时或重试等传输不确定性还可能造成少记或重复,因此该指标仅适合观察调用分布。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-product-analysis
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The function is explicitly designed to parse the project-root .env file and inject its contents into the process environment. Even if intended for harmless metadata defaults, this gives a telemetry-related module access to potentially sensitive secrets stored in .env and normalizes broad secret ingestion in code that does not require it.

Content

Scanner excerpt · scripts/_tracker.py (reported line 26)May include surrounding context.

python
_ROOT_DIR = Path(__file__).parent.parent

def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Constructing and opening the project-root .env file as part of module behavior creates unnecessary exposure of local configuration and secrets to a telemetry component. In this skill context, telemetry is ancillary to product analysis, so accessing repository-level configuration is less justified and more suspicious than in core application bootstrap code.

Content

Scanner excerpt · scripts/_tracker.py (reported line 27)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Automatically executing _load_env_file() at import time causes implicit secret/config ingestion whenever the module is imported, without any caller opt-in. This hidden side effect increases risk because other code paths may unintentionally trigger local secret loading, and any downstream code in the same process can then observe those injected values through os.environ.

Content

Scanner excerpt · scripts/_tracker.py (reported line 42)May include surrounding context.

python
if key and key not in os.environ:
                os.environ[key] = value

# 模块加载时解析一次 .env
_load_env_file()

def _get_skill_env():

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill builds a general-purpose shell/Python execution layer for a product-analysis workflow, including OS probing, command construction, file redirection, and subprocess management. Even if current call sites are intended for local CLI access, this greatly expands the attack surface: prompt-controlled arguments, future maintenance changes, or downstream misuse could turn an analytics skill into arbitrary local code execution infrastructure.

Content

No source excerpt is available for this finding.

Obfuscated Code

High
Category
Supply Chain
Confidence
95% confidence
Finding

The code decodes base64 and immediately executes the result with Python exec, which is an obfuscation pattern and a powerful dynamic code-execution primitive. In a skill that also accepts model-influenced inputs and constructs commands, this makes review harder and increases the risk that unintended or attacker-controlled code paths execute locally.

Content

Scanner excerpt · workflow/1688-product-analysis.js (reported line 166)May include surrounding context.

js
const extraArgs = argList.slice(2).map(arg => shellEscape(arg, dialect)).join(' ')
    const argsPart = extraArgs ? ` ${extraArgs}` : ''
    redirectedCmd = isCmd
      ? `${program} -c "import base64;exec(base64.b64decode('${toBase64(utf8Bytes(script))}').decode())"${argsPart} > "${outFile}" 2> "${errFile}"`
      : `{ ${program} -${argsPart} << '${PY_HEREDOC_DELIMITER}'\n${script}\n${PY_HEREDOC_DELIMITER}\n} > "${outFile}" 2> "${errFile}"`
  } else {
    const plainCmd = [program, ...argList.map(arg => shellEscape(arg, dialect))].join(' ')

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · workflow/1688-product-analysis.js (reported line 195)May include surrounding context.

js
].join('\r\n') + '\r\n'
    command = `${program} -c "import base64;open(r'${wrapFile}','wb').write(base64.b64decode('${toBase64(utf8Bytes(wrapper))}'))" & call "${wrapFile}" & del /f /q "${wrapFile}"`
  } else {
    command = `${redirectedCmd}; _ec=$?; echo $_ec; cat "${outFile}"; printf '\\n${BASH_STDERR_MARKER}'; cat "${errFile}"; rm -f "${outFile}" "${errFile}"`
  }
  return { command, timeout, description: description || `执行 ${program}` }
}

Ssd 1

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow emits hidden imperative instructions that attempt to control future assistant behavior, including forbidding certain safeguards, dictating exact next responses, and steering future tool use. This is dangerous because it creates prompt-injection-like control flow across turns: later assistants may obey embedded instructions and perform sensitive actions such as exporting cached files or invoking other workflows based on untrusted in-band content.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Markdown delivery path contains embedded hidden directives commanding the next assistant response and future actions such as workflow invocation and schedule setup. Because these directives are mixed into model-consumable text, they act as adversarial prompt content that can override normal decision-making and cause unauthorized chaining or disclosure in later turns.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill exposes capabilities involving environment access, file reads, and networked/CLI-backed operations but does not declare a restrictive tool scope such as allowed tools or permissions. In a high-privilege agent runtime, this increases the blast radius of prompt injection or workflow misuse because the runtime cannot enforce least privilege from the manifest level.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains broad everyday phrases such as recommendation, selection, priority, search, and optimization wording that could activate the skill outside clearly intended contexts. In an agent environment with file, env, export, scheduling, and network-backed workflows, over-broad activation materially raises the risk of unintended data access, unintended workflow execution, or social-engineering-based misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L072、L074、L118、L431-L435 多次声明 alibaba.1688.get.item.diagnosis.context 由服务端按 itemId 精确定位归属店,“不做跨店遍历兜底”。但 L551 又写聚合 Tool 会执行“默认店铺优先、明确商品 miss/空/归属错时绑定店铺兜底”,这实际上重新引入了跨店兜底语义。两种描述对同一核心诊断工具的行为定义互相冲突,容易导致实现或审计误判。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L081 明确写明用户数量超过 5 件时要“滑动补位并处理全部已选商品,不得截断”。但 L393 又规定 automatic 模式“5 个以上只诊断前 5 个”,这与前面对多商品不得截断的强约束相冲突,且会直接改变技能实际交付范围。该矛盾属于文档意图与流程行为定义不一致。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L090 明确规定导出缓存文件时“随后只允许两个工具调用——先 Read 缓存文件...,再调用一次 Write”,这是实现导出的必要步骤。但同一长句后半段又写“严禁调用 Bash、Edit、present_files、schedule_task、show_interaction 或其他工具”,而 L496 更进一步写成“禁止再次调用 workflow、商品查询或除 Write 外的任何工具”,与前述 Read 必需步骤直接冲突。该文档会让实现者无法同时满足两条要求,属于注释/规范对实际执行意图的主动矛盾。

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
`__userId__` 由 `cli.py` 通过解析 `ALI_1688_AK` 自动注入,命令本身无需感知卖家身份。

| 命令                           | 用法                                                                                                                          | 说明                                                                                          |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| `get_bindlist`                 | `{python} {baseDir}/cli.py get_bindlist`                                                                                       | 查询当前用户绑定的多店铺列表(含各店铺 loginId)                                              |
| `multi_shop_product_analysis`  | `{python} {baseDir}/cli.py multi_shop_product_analysis [--shop_name <店铺名>] [--date_type <日期类型>] [--device <设备>] [--max_total_rows <行数>] [--no-lite]`         | 批量查询多店铺异常商品汇总(默认所有绑定店铺,支持指定店铺)                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
`__userId__` 由 `cli.py` 通过解析 `ALI_1688_AK` 自动注入,命令本身无需感知卖家身份。

| 命令                           | 用法                                                                                                                          | 说明                                                                                          |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| `get_bindlist`                 | `{python} {baseDir}/cli.py get_bindlist`                                                                                       | 查询当前用户绑定的多店铺列表(含各店铺 loginId)                                              |
| `multi_shop_product_analysis`  | `{python} {baseDir}/cli.py multi_shop_product_analysis [--shop_name <店铺名>] [--date_type <日期类型>] [--device <设备>] [--max_total_rows <行数>] [--no-lite]`         | 批量查询多店铺异常商品汇总(默认所有绑定店铺,支持指定店铺)                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
| 命令                           | 用法                                                                                                                          | 说明                                                                                          |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| `get_bindlist`                 | `{python} {baseDir}/cli.py get_bindlist`                                                                                       | 查询当前用户绑定的多店铺列表(含各店铺 loginId)                                              |
| `multi_shop_product_analysis`  | `{python} {baseDir}/cli.py multi_shop_product_analysis [--shop_name <店铺名>] [--date_type <日期类型>] [--device <设备>] [--max_total_rows <行数>] [--no-lite]`         | 批量查询多店铺异常商品汇总(默认所有绑定店铺,支持指定店铺)                                   |
| `get_abnormal_offers`          | `{python} {baseDir}/cli.py get_abnormal_offers [--date_type <日期类型>] [--device <设备>] [--NEWTON_SHOP_LOGIN_ID <loginId>] [--no-lite]`     | 查询异常商品列表(支付下跌、访客下跌等),支持指定店铺                                          |
| `alibaba.1688.get.item.diagnosis.context`   | `{python} {baseDir}/cli.py alibaba.1688.get.item.diagnosis.context --item_id <itemId>`                                                       | 核心 Workflow 正式诊断入口;内部解析商品归属并聚合基础数据、同款和行动点,返回命中商品的 loginId |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
| `get_abnormal_offers`          | `{python} {baseDir}/cli.py get_abnormal_offers [--date_type <日期类型>] [--device <设备>] [--NEWTON_SHOP_LOGIN_ID <loginId>] [--no-lite]`     | 查询异常商品列表(支付下跌、访客下跌等),支持指定店铺                                          |
| `alibaba.1688.get.item.diagnosis.context`   | `{python} {baseDir}/cli.py alibaba.1688.get.item.diagnosis.context --item_id <itemId>`                                                       | 核心 Workflow 正式诊断入口;内部解析商品归属并聚合基础数据、同款和行动点,返回命中商品的 loginId |
| `alibaba.1688.get.offer.data`               | `{python} {baseDir}/cli.py alibaba.1688.get.offer.data --offer_id <商品ID> [--modules <模块列表>] [--NEWTON_SHOP_LOGIN_ID <loginId>]` | 兼容或自由查询商品模块;不再是核心 Workflow 正式诊断路径  |
| `get_item_overview`            | `{python} {baseDir}/cli.py get_item_overview`                                                                                  | 获取商品概览统计(商品总数、有销售商品数、总销售额等),Step 0.5 前置数据收集                  |
| `get_shop_data`                | `{python} {baseDir}/cli.py get_shop_data`                                                                                      | 获取店铺维度数据(支付金额、支付买家数、在线商品数),作为 `score_and_select` 的评分基准        |
| `score_and_select`             | `{python} {baseDir}/cli.py score_and_select --shop_total '<get_shop_data返回JSON>' [--strategy <策略>] [--limit <N>] [--top_n <N>]` | 五维度评分分层全店商品,返回 Top-N 高分排序商品(`products`,正向选品再筛 S/A/B)与全部 C 级候选(`c_grade_candidates`,供 Step 0.5 使用) |
| `search_offer_by_keyword`      | `{python} {baseDir}/cli.py search_offer_by_keyword --keyword <关键词> [--page <页码>] [--page_size <每页数量>]`                  | 通过关键词搜索店铺商品,用于 Step 1 情况B 辅助定位商品                                        |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
| `alibaba.1688.get.item.diagnosis.context`   | `{python} {baseDir}/cli.py alibaba.1688.get.item.diagnosis.context --item_id <itemId>`                                                       | 核心 Workflow 正式诊断入口;内部解析商品归属并聚合基础数据、同款和行动点,返回命中商品的 loginId |
| `alibaba.1688.get.offer.data`               | `{python} {baseDir}/cli.py alibaba.1688.get.offer.data --offer_id <商品ID> [--modules <模块列表>] [--NEWTON_SHOP_LOGIN_ID <loginId>]` | 兼容或自由查询商品模块;不再是核心 Workflow 正式诊断路径  |
| `get_item_overview`            | `{python} {baseDir}/cli.py get_item_overview`                                                                                  | 获取商品概览统计(商品总数、有销售商品数、总销售额等),Step 0.5 前置数据收集                  |
| `get_shop_data`                | `{python} {baseDir}/cli.py get_shop_data`                                                                                      | 获取店铺维度数据(支付金额、支付买家数、在线商品数),作为 `score_and_select` 的评分基准        |
| `score_and_select`             | `{python} {baseDir}/cli.py score_and_select --shop_total '<get_shop_data返回JSON>' [--strategy <策略>] [--limit <N>] [--top_n <N>]` | 五维度评分分层全店商品,返回 Top-N 高分排序商品(`products`,正向选品再筛 S/A/B)与全部 C 级候选(`c_grade_candidates`,供 Step 0.5 使用) |
| `search_offer_by_keyword`      | `{python} {baseDir}/cli.py search_offer_by_keyword --keyword <关键词> [--page <页码>] [--page_size <每页数量>]`                  | 通过关键词搜索店铺商品,用于 Step 1 情况B 辅助定位商品                                        |
| `get_same_offer_competition`   | `{python} {baseDir}/cli.py get_same_offer_competition --offer_id <商品ID> [--NEWTON_SHOP_LOGIN_ID <loginId>]`                    | 兼容或自由查询同款 V2 对标事实;核心 Workflow 由聚合 Tool 内部调用            |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI unconditionally attempts to send usage telemetry after every dispatched command via _tracker.report_skill_usage(api_name=cmd) and does so silently. Even though the payload shown here is limited to the command name, this creates a privacy and transparency issue because users are not informed and are not given consent, opt-out, or configuration controls in this execution path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains mandatory user-facing strings in Chinese and repeatedly requires exact Chinese replies and prompts later in the document. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.