Back to skill

Security audit

零售与门店经营专家

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a local retail reconciliation tool, but it under-discloses a persistent five-use counter and subscription gate, so it should be reviewed before installation.

Install only if you are comfortable running a Chinese-language local Node.js reconciliation tool that may process sensitive business tables and create a small usage-counter file in your home directory. Review the five-use limit and subscription behavior before providing real business data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (89)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding describes a store transfer/inventory-only implementation behind documentation that promises broad retail, franchise, rebate, consignment, and hotel-audit capabilities. That discrepancy is dangerous because it can lead operators to trust outputs in domains with no supporting logic, creating false assurance rather than direct code exploitation.

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The module docstring and all implemented checks are specific to '预付卡消费核销核对', including card balances, recharge, consumption, refunds, and recognized revenue. The manifest instead describes routing among 17 retail/store-operation subskills such as ad rebates, franchise settlement, consignment settlement, and hotel night audit, with no mention of prepaid-card reconciliation as part of the declared scope.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The header comment asserts the public version is 'pure local' and performs no counting or upsell, but the code persists a local usage counter, enforces a five-use gate, and prints subscription purchase messaging. This is dangerous because it is a deliberate mismatch between declared privacy/behavior guarantees and actual execution, undermining informed consent and trust; in a tool that may process sensitive business tables, false claims about telemetry and restrictions materially increase user risk.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill’s primary display name, summary, and descriptions are all presented in Chinese, and even the `display_name_en` field is set to the same Chinese text rather than an English option. This indicates a language constraint without any documented user opt-in or justification for limiting the skill to Chinese.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The manifest's user-facing name field is provided in Chinese ("零售与门店经营专家"), and all listed subskill names and keywords are likewise Chinese-only. This may amount to a language/locale constraint without an explicit user choice or documented justification.

Static analysis

No suspicious patterns detected.