Back to skill

Security audit

优惠券查询·场景快取

Security checks across malware telemetry and agentic risk

Overview

This skill locally matches coupon requests to a bundled promotional-link list, with disclosed third-party links and no evidence of credential access, persistence, or hidden execution.

Safe to install for normal coupon lookup if you are comfortable receiving third-party promotional links. Verify link destinations before opening them or entering information, and treat the Feishu submission form as an external site for voluntarily sharing coupon details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill’s declared purpose is coupon discovery/claiming, but it also instructs users to submit promotional links through an external Feishu form. This hidden scope expansion creates an undocumented data-ingestion pathway that can be abused for phishing, malicious link seeding, or collection of user-submitted data outside the expected skill behavior.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Accepting user-contributed activity links is not necessary for a coupon-finding skill and introduces an unnecessary trust boundary. Even with claimed manual review, this can become a channel for malicious promotions, scam links, or social engineering content that may later be redistributed to users.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The dataset includes a private-domain / enterprise-WeChat acquisition campaign entry ('美团外卖私域加企微') that appears intended to funnel users into off-platform retention or contact channels, not simply help them find discounts. In a coupon-finder skill, this is dangerous because it can socially engineer users into joining marketing funnels or private contact networks under the guise of coupon assistance, increasing risk of spam, profiling, and off-platform manipulation.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger phrases are broad enough to overlap with ordinary conversation such as asking generally about discounts or deals. Overbroad activation can cause the skill to trigger unexpectedly, increasing the chance that users are steered to promotional links or external resources without having intended to invoke this specific capability.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The examples in the trigger section expand activation scope with ambiguous everyday phrases and also mix in a separate 'share activity' workflow. This makes invocation boundaries unclear and increases the risk of unintentional activation into a feature that can redirect users to external links or submission forms.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.