Back to skill

Security audit

承运商指数查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward carrier logistics analysis helper, but users should avoid using its plaintext HTTP portal links for sensitive operational data.

Install only if you intend the agent to read the specific spreadsheet you provide and use the listed Jingwe/JDL portal pages for carrier analysis. Prefer verified HTTPS access to the portal, confirm the destination before downloading anomaly details, and avoid exposing sensitive carrier or operational data over plaintext HTTP.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Operational Portal Access Uses Unencrypted HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation condition is overly broad: any query about a carrier's logistics index score could trigger the skill without clearly constraining required inputs, scope, or safety checks. In a skill that reads local files and initiates web/download actions, ambiguous invocation increases the chance of unintended file access, accidental external navigation, or execution in the wrong user context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to read local Excel/CSV files, access external websites, and trigger downloads, but it does not present explicit user warnings, consent boundaries, or restrictions on what files/URLs may be touched. This creates a real risk of unauthorized local data exposure, unintended network access, and downloading sensitive operational details, especially because the skill also references anomaly-detail exports tied to carrier and date filters.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.