Back to skill

Security audit

jys-skill-suite-AI-shop-drama

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real short-drama advertising workflow, but its bundled content and rules can generate unsafe or under-disclosed promotional and scam-themed scripts.

Review this skill before installing if you will use it for public or commercial content. Treat generated scripts as drafts requiring human compliance review, especially for health, child, elder, chemical, food, or emergency-use claims. Avoid reusing blacklisted-product scripts, narrow invocation triggers where possible, and approve any writes to the project workspace or shared skill database deliberately.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (46)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill instructs the agent to read and write workspace files (`status.md`, shared assets, and stage files) but does not declare permissions accordingly. This creates a capability-transparency problem: users and enforcement layers may not realize the skill can modify local state, increasing the chance of unintended file access or persistence. In this context, the risk is elevated because the workflow is designed to persist and update project status across sessions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill is presented as a content-creation workflow entrypoint, but its documented behavior includes filesystem migration, validation, and maintenance-style operations beyond simple routing. When a skill's stated purpose does not clearly disclose operational side effects like rewriting status files or performing suite-wide inspection, users may invoke it expecting benign creative assistance while it modifies local project state. Because the skill also instructs the agent to fully trust and execute subordinate skill files, the mismatch increases the chance of hidden or unexpected actions being carried out.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The file metadata explicitly marks the product as blacklisted and not to be stocked, yet the script later contains a complete promotional sales segment for that same product. This creates a policy-bypass condition where downstream agents or users may still generate, approve, or publish prohibited marketing content despite the documented restriction.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
This is a true contradiction between documentation and operative content: the asset says the item is non-stocked/blacklisted, but the body actively markets it, provides benefit claims, urgency tactics, and directs the audience to purchase. In an agent skill that may be reused automatically, this inconsistency is especially dangerous because the prohibited content is embedded in a ready-to-publish script and can propagate at scale.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The metadata explicitly marks the product as '黑名单,不入库' (blacklisted, do not enter into inventory), yet the script later actively endorses and sells that same product. This creates a policy bypass risk: downstream agents or operators may trust the promotional script over the metadata and inadvertently surface, store, or market a product that has already been disallowed.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This script segment goes beyond a neutral drama template and embeds detailed persuasive sales language, urgency cues, pricing claims, and direct purchase instructions such as clicking an avatar and buying from the product window. In an agent skill, that creates a risk of hidden advertising or unauthorized commercial persuasion, especially if the user did not explicitly ask for shoppable sales copy.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The script shifts from fictional short-drama content into concrete health efficacy claims for a consumable product, including symptom relief and functional improvement claims. This is dangerous because users may treat the narrative as endorsement or advice, especially when the product is framed as traditionally validated and personally effective.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The health-remedy narrative is not justified by the stated purpose of a short-drama workflow skill and introduces disease-style explanations, remedy preparation steps, and claims of improvement. In this context, the skill is more dangerous because it can mass-produce persuasive pseudo-medical marketing scripts under the cover of entertainment content.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The rule requiring 'deep transformation' to evade strict duplicate detection encourages imitation of existing scripts in a way that can facilitate plagiarism or IP infringement rather than original creation. In a workflow explicitly designed to mass-produce sales dramas, this increases the risk of systematic content laundering under the guise of rewriting.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The audience guidance explicitly characterizes older women as having poor logic and low cognition, then instructs creators to exploit that perceived vulnerability with simplified, emotionally manipulative content. This is dangerous because it operationalizes discriminatory targeting and deceptive persuasion toward a potentially vulnerable demographic in a commercial setting.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Several triggers such as `JYS`, `短剧脚本`, and `使用JYS` are broad enough to match ordinary conversation, increasing the likelihood that the skill activates unintentionally. In this skill, unintended activation is more concerning because activation can lead to reading workspace state, routing into other stage files, and writing project status, rather than just generating ephemeral text.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
This file gives step-by-step instructions for designing and refining a '诈骗因果链' (fraud/scam causal chain), including how an attacker approaches a target, gains information or permissions, creates pressure, induces key actions, and causes loss. Even though it is framed as '防诈' and for drama construction, it operationalizes scam methodology in a reusable workflow, which can be repurposed to improve real-world fraud tactics.

Missing User Warnings

Low
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to append generated script content to `JYS_WORKSPACE/s4-workspace.md` after user confirmation, but it does not warn about file modification side effects or constrain how file writes are authorized. In an agent environment with filesystem tools, this can lead to unintended persistence, overwriting/poisoning of shared workspace state, or user surprise about durable changes.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file explicitly instructs the model to append a purchase-oriented call to action ('点击视频左下角链接') as part of the required output, without any disclosure, consent check, or safety guard for commercial persuasion. In an agent skill, this can cause the system to generate covert advertising or transactional nudges that the user may not expect, especially because the workflow is designed to operationalize product promotion across scripted content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The documented interaction cue includes very broad audience-facing phrases such as asking users to comment or use common everyday expressions, which can overlap with normal conversation and unintentionally trigger the skill. In a multi-skill agent environment, overly generic triggers increase the chance of accidental activation, context hijacking, or unintended workflow entry when users are not explicitly invoking this drama-writing skill.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script explicitly markets a chemical household product as suitable for 'elderly and children' while omitting basic safety disclosures such as keeping it out of reach of children, avoiding ingestion, and using only as directed in ventilated storage spaces. In this skill's context, the claim is embedded in persuasive sales copy and repeated endorsements, which can normalize unsafe handling and mislead users into treating the product as harmless.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The flagged dialogue explicitly endorses sexist gender norms by saying a wife should be 'trained' to work after marriage and 'disciplined' by in-laws. Even though this appears in a fictional drama script rather than executable code, the skill is designed to generate reusable content, so retaining this language can propagate discriminatory messaging into produced scripts at scale.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The script markets a food product for a 6-year-old child who has had prolonged refusal to eat and even faints from hunger, then reassures viewers that the product is safe for children and elders without any medical caution. In a commercial script, this can normalize using a promoted product as an implied solution to a potentially serious pediatric health issue, discouraging appropriate medical evaluation and overstating safety claims.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The script contains explicit commercial promotion, pricing, discount language, and direct calls to purchase through a profile or storefront, but provides no disclosure that the content is advertising. In an agent skill, this can mislead users into treating sponsored persuasion as neutral assistance and can cause the agent to steer users toward purchases without transparency.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The script explicitly states the product can be applied to children and suggests specific use cases, including comfort and mosquito-related benefits, without any safety qualification, age restrictions, allergy warnings, or instruction to follow approved labeling. In a commercial script, this can normalize unsafe pediatric use and create misleading health-adjacent claims for a product that may irritate skin or be unsuitable for infants or sensitive users.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The script depicts applying medicated cooling oil to a distressed young child immediately after heat exposure, presenting it as helpful without any warning about age appropriateness, skin/eye irritation, ingestion risk, or the need to prioritize professional medical guidance. Because this is a shopping/drama skill designed to generate persuasive scripts, the scene can normalize unsafe first-aid behavior and encourage caregivers to copy it in real emergencies.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The script broadly markets the cooling oil for 'students,' 'families,' 'moms with kids,' and 'all ages' style use cases while omitting safety limitations, contraindications, and age-specific caution. In a sales-oriented skill, that context makes the omission more dangerous because the content is intended for scalable promotional reuse and may lead users to apply a medicated topical product to children or vulnerable people inappropriately.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script explicitly depicts using cross-hospital patient records and broad hospital searching to identify a private individual without consent, legal basis, or any privacy guardrails. In a reusable workflow/script library, this can normalize or operationalize unlawful access to sensitive medical information and doxxing-style behavior by assistants or users.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The product pitch makes medical-style and safety-relevant claims around heat illness, driving fatigue, and broad family use while omitting warnings that the product is not a treatment for heat stroke, is not appropriate as a substitute for medical care, and may be unsafe for some users or situations. In this skill context, the dramatic rescue narrative strengthens the implied efficacy and can mislead users into relying on the product in risky circumstances.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The product pitch makes multiple health-adjacent and consumption-related claims such as relief for throat discomfort, sleep issues, bloating, and smoker discomfort, while also using scarcity and price-pressure tactics without cautions, substantiation, or suitability warnings. This can mislead users into treating the product as a remedy and encourages impulsive purchasing without adequate disclosure.

Static analysis

No suspicious patterns detected.