Back to skill

Security audit

StyleBuddy

Security checks for vulnerabilities and agentic risk

Overview

StyleBuddy appears to be a local wardrobe assistant, but it needs review because it asks for clothing photos and profile-like data while overstating image AI features and using broad activation triggers without clear privacy controls.

Install only if you are comfortable with a Chinese-language wardrobe assistant that stores clothing photos, wardrobe records, preferences, wishlist data, and backups locally. Review or change the default gender preference and triggers before use, and do not rely on the advertised automatic image recognition unless the publisher adds a real implementation and clear privacy controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (69)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming multimodal wardrobe intake and styling assistance when those capabilities are not implemented is a trust and review integrity problem. Users may upload photos or personal profile information believing they will receive one function while the skill may be doing something else entirely or collecting data unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The progress document explicitly states that images and templates are 90% oriented toward female users, establishing a gender-focused default without any indication of user opt-in or preference selection. In a styling assistant, this can lead to biased recommendations, exclusion of non-female users, and potentially inappropriate personalization based on assumed gender presentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes photo-based wardrobe intake and a user profiling system that records preferences, but gives no privacy notice, retention policy, consent flow, or explanation of how personal data is handled. Because clothing photos and preference profiles can reveal sensitive lifestyle, body, location, and behavioral information, users may be exposed to unexpected collection or misuse of personal data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README emphasizes natural, keyword-free interaction and broad capability descriptions without defining clear activation boundaries. In an agent ecosystem, this can cause the skill to engage on ambiguous everyday fashion-related requests, increasing the chance of unintended invocation, context capture, or overreach into conversations the user did not mean to route to this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example trigger phrase "今天穿什么?" is common everyday speech and is likely to appear in normal conversation. If the platform uses natural-language routing, such a generic phrase can cause accidental activation and unnecessary access to user context, photos, wardrobe data, or profiling features.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as usable through broad natural conversation without clear trigger boundaries. In agent ecosystems, overly broad invocation language can cause unintended routing, prompt capture, or activation in contexts where the user did not clearly intend to call this skill, increasing the chance of accidental data exposure or overreach.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage examples frame activation as generic chat rather than as bounded commands or clearly scoped intents. That makes accidental invocation more likely, especially in a multimodal/personal-data context, and can lead to the skill processing wardrobe, image, or contextual information when the user expected ordinary conversation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The spec directs the dataset toward a 90% female clothing image distribution by default, embedding a demographic bias into system behavior without user choice or documented necessity. This can lead to discriminatory or mismatched recommendations, especially for users whose style, identity, or needs do not align with the assumed default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The task spec explicitly includes calendar reading, external API calls, image search, AI generation, and backup/restore, but does not require consent flows, disclosure, or limits on what personal data is collected, transmitted, or persisted. In a wardrobe/lifestyle skill, these features can expose sensitive personal routines, images, and preference data to third parties or backups without the user understanding the privacy implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The additional note reinforcing a female-first default further operationalizes biased behavior across images and templates without opt-in. In this skill context, that increases the likelihood that the product systematically personalizes content based on an assumed gendered preference rather than explicit user input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains very generic clothing-related phrases such as '衣服', '穿搭', and '搭配', which are likely to appear in ordinary conversation. This can cause the skill to activate unintentionally, increasing the chance of inappropriate interception of user queries and expanding the skill's effective access beyond clearly intentional invocations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON data file uses Chinese names, styles, occasions, and descriptions exclusively, which can impose a specific language/locale on downstream skill behavior if consumed directly for user-facing output. The file does not document any opt-in, alternative locale support, or region-specific justification for the language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON dataset uses Chinese names, descriptions, keywords, and tips throughout, which effectively forces a single language/locale. The policy explicitly flags language or locale constraints when the skill does not offer user choice or document a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON dataset uses Chinese for IDs, names, categories, occasions, item labels, colors, and tips throughout the file, which effectively constrains the skill's natural-language content to a single language. Under the policy rule for language/locale constraints, this is a concern when no user opt-in or documented locale justification is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This config hard-codes gender: "female" as a user preference, which can impose a fixed demographic setting rather than offering a user-selected option. Under the policy, forcing a specific user-facing preference or locale-like constraint without explicit opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's natural-language content, including comments, category labels, occasions, tips, and console output, is entirely in Chinese with no indication of language choice or user opt-in. This can violate a language/locale policy when a skill is expected to accommodate user preference rather than enforcing a single language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.