Back to skill

Security audit

Ozon-关键词选品专家 | 青虎AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Ozon keyword-research helper that uses Qinghu's API with user-authorized calls, with the main caution being automatic export of larger result sets to local files.

Install this if you are comfortable using Qinghu's API for Ozon keyword research, providing or exposing a Qinghu token, and having larger result sets exported to local files. Confirm the planned tool calls and expected credit use before letting it run, and avoid using it with business data you do not want stored in local export files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill declares it 'must' trigger for a broad class of common Ozon research requests, which can cause the agent to route users into this skill too aggressively. Because the skill then encourages credential collection and paid external API use, over-broad activation increases the chance of unnecessary data disclosure, unintended charges, and reduced user control over tool selection.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to automatically export large results to a file and even reuse cached local file paths, without requiring a separate upfront warning or consent for local file creation. This can create unanticipated local artifacts containing potentially sensitive business data, and the mention of exposing file paths raises additional privacy and environment-information leakage concerns.

Static analysis

No suspicious patterns detected.