Back to skill

Security audit

跨境电商产品合规速查

Security checks for vulnerabilities and agentic risk

Overview

This is a static cross-border compliance lookup skill that reads bundled reference files and formats a report, with no evidence of hidden access or unsafe behavior.

Install this if you want a static compliance checklist and report generator for cross-border ecommerce products. Treat outputs as starting-point guidance, especially for legal, regulatory, medical-device, food, cosmetics, or export decisions, and confirm current requirements with official regulators or qualified compliance professionals before acting.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include broad, generic expressions such as certification or export-compliance queries that can overlap with normal conversation, increasing the chance the skill is invoked outside the user's intended context. In a compliance skill, unintended activation can cause irrelevant regulatory guidance to be injected into conversations, confusing users or displacing more appropriate handling.

Static analysis

No suspicious patterns detected.