Back to skill

Security audit

食品与餐饮合规专家

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese food and catering table-checking skill with no network behavior, but it keeps a small local usage counter and should not be treated as a regulator or auditor.

Install only if you are comfortable running a local Node/Bash skill on pasted business or compliance tables. It does not send data over the network in the inspected artifact, but it will create a local usage-count file in your home directory and its Chinese compliance output is advisory, not a substitute for legal, regulatory, food-safety, or audit review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
Claiming automatic triage across six food/catering compliance checks while only supporting fresh-loss review creates a substantial mismatch between represented and actual assurance. In real use, this can produce false confidence around food-safety and inventory compliance, especially when users expect the tool to reject unsupported inputs rather than silently under-scope them.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
Claiming automatic triage across six food/catering compliance checks while only supporting fresh-loss review creates a substantial mismatch between represented and actual assurance. In real use, this can produce false confidence around food-safety and inventory compliance, especially when users expect the tool to reject unsupported inputs rather than silently under-scope them.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
Claiming automatic triage across six food/catering compliance checks while only supporting fresh-loss review creates a substantial mismatch between represented and actual assurance. In real use, this can produce false confidence around food-safety and inventory compliance, especially when users expect the tool to reject unsupported inputs rather than silently under-scope them.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
Claiming automatic triage across six food/catering compliance checks while only supporting fresh-loss review creates a substantial mismatch between represented and actual assurance. In real use, this can produce false confidence around food-safety and inventory compliance, especially when users expect the tool to reject unsupported inputs rather than silently under-scope them.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
Claiming automatic triage across six food/catering compliance checks while only supporting fresh-loss review creates a substantial mismatch between represented and actual assurance. In real use, this can produce false confidence around food-safety and inventory compliance, especially when users expect the tool to reject unsupported inputs rather than silently under-scope them.

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill name, summary, descriptions, trigger phrases, and usage text are entirely Chinese-facing, while `display_name_en` still repeats the Chinese name and `description_en` is only partial. There is no indication that users may choose another language or that the skill is intentionally restricted to a China-specific regulatory locale, which matches the language/locale policy concern.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword set for this sub-skill includes broad terms such as '免费' and '对账', which are common across many unrelated requests. This can cause unintended routing to the BOM checking skill, leading the agent to process the wrong data or produce compliance conclusions for an unintended task.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This keyword list again contains generic triggers such as '免费' and '核对', plus loosely related terms like '餐具消毒记录', which may overlap with adjacent canteen workflows. In an auto-routing system, broad triggers increase the chance that unrelated tables are misclassified and that the system emits incorrect compliance judgments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The factory inspection sub-skill uses generic keywords such as '免费' and broad compliance language that can match many food-quality queries. Because this skill may generate audit-style conclusions, ambiguous activation can lead to false assurance, missed issues, or user confusion about which checks were actually performed.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The fresh-loss checker includes highly generic trigger words like '免费', '对账', and '核对', which are common in many accounting or inventory tasks. This raises the risk of accidental invocation and incorrect discrepancy analysis on tables that do not represent fresh inventory loss, undermining reliability of the compliance workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The lab sample retention sub-skill mixes precise terms like CMA/CNAS with generic activation words such as '免费' and '核对'. In a compliance assistant that auto-selects sub-skills from user text, these weak triggers can cause wrong routing and flawed conclusions about chain-of-custody or retention periods.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This code file contains its user-facing documentation and guidance entirely in Chinese, including usage contract, warnings, and result explanations. The file does not indicate that the skill is intentionally limited to Chinese-speaking users or offer any language/locale opt-in, which can violate a language/locale policy for general-purpose skills.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file’s natural-language contract, guidance, findings, and remediation text are written entirely in Chinese and assume Chinese-language operation. There is no indication that users may choose another language or locale, which can violate a language-choice policy when the skill is used in broader contexts.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The file’s user-facing comments, messages, advice strings, and output text are consistently written in Chinese, and there is no indication that users can opt into another language. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest says this skill covers exactly six sub-skills, including 食品出厂检验与留样记录核对, and emphasizes auto-triage into one of those declared skills. This file adds extra paid-mode capabilities such as 不合格品处置闭环, 检验数据与报告一致性, 同批产品跨生产线/跨班次, and 分产品×分班次汇总整改清单, which go beyond the described six-skill scope rather than merely implementing the stated record-checking behavior.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest promises that pasting a table will automatically route to the proper sub-skill and provide line-by-line conclusions, and says when material is insufficient it should honestly report missing columns and otherwise not give conclusions. Here, execution is also conditioned on paid flags (full/credit/token), causing some checks to be withheld for non-paid requests even when input is sufficient, which is a behavior-level mismatch with the manifest description.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
This JavaScript file emits user-facing descriptions, errors, findings, and remediation text entirely in Chinese across comments, returned messages, and result fields. The policy allows locale constraints only when the skill explicitly offers a language choice or clearly documents and justifies the restriction; this file does not present an opt-in or configurable language selection in code.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file-level natural-language documentation, user-facing advice, and output strings are written entirely in Chinese, which effectively constrains the skill's interaction language. The file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific compliance context.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The file’s user-facing description, usage text, errors, and output are all written in Chinese, and the skill branding explicitly targets a Chinese-language experience. There is no indication that users may choose another language or that the language restriction is a documented, region-specific requirement, which fits the language/locale policy-violation category.

Static analysis

No suspicious patterns detected.