Back to skill

Security audit

电商爆款文案生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese e-commerce copywriting helper with no evidence of hidden access, persistence, network use, or destructive behavior.

Install only if you want Chinese-language copywriting guidance for Chinese e-commerce platforms. Treat sales figures, efficacy claims, discounts, testimonials, certifications, and scarcity language as placeholders that must be truthful, evidenced, and compliant with the target platform and applicable advertising rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
声明描述的是一个较完整的电商文案生成技能,覆盖多类文案产出与竞品分析;但提供的代码块功能明显更窄,核心行为只是“商品标题模板生成器”。它不会分析竞品,不会生成详情页文案,不会提炼卖点,只是使用输入的 selling_points 拼接到标题中;也不会生成独立的促销活动文案,只是在标题中插入 promotion 文本。平台支持方面,代码只对 taobao、pinduoduo、douyin 提供专门模板,其他平台走通用逻辑,不能充分支撑‘京东卖家专用支持’这一表述。因此描述与实际行为存在显著范围不一致,属于能力夸大型不匹配。

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill name, description, and usage guidance are entirely in Chinese and present the skill as a general ecommerce copywriting tool rather than a clearly China-only or Chinese-only tool. Under SQP-3, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill encourages generation of marketing copy using examples like quantified performance claims, social proof, urgency, and promotional assertions, but does not warn that such claims may require substantiation and legal review. In an ecommerce context, this can lead users to publish false or non-compliant claims, creating regulatory, consumer-protection, and platform-enforcement risk.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file presents all platform rules and copywriting guidance exclusively in Chinese, and does not indicate that the language is optional or limited to a China-specific audience. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file’s docstrings, CLI error messages, output fields, and generated content are all hard-coded in Chinese, indicating the skill is designed to operate in a single language. The policy requires flagging language or locale constraints when they are imposed without user opt-in or a clearly documented justification.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown file presents all instructions and templates exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy criterion, forcing a single language without opt-in can be a policy concern.

Static analysis

No suspicious patterns detected.