Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/run.mjs --sample # 先看样例
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local food-label ledger checker whose code and permissions match its stated purpose, with only minor documentation and locale limitations to note.
Install only if you want a local Node-based checker for Chinese food-label and ingredient-ledger materials. Treat its results as narrow consistency checks, not as a full legal compliance determination, because several checks are explicitly not included and it does not inspect PDFs, images, label layout, supplier evidence, or full regulatory validity.
Referenced artifact was not completely inspected
node scripts/run.mjs --sample # 先看样例
Referenced artifact was not completely inspected
node scripts/run.mjs --sample # 先看样例
Referenced artifact was not completely inspected
node scripts/run.mjs --sample # 先看样例
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
This JavaScript file contains natural-language descriptions, guidance, and output text entirely in Chinese, including the tool contract and remediation messages, with no indication that language choice is optional. Under the policy rule, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly documented and justified as region-specific.
The comment above SAMPLE_TEXT says the appended five additional checks also all pass and that the whole table has zero hits, implying those checks are part of this engine's effective behavior. However, the module documentation and runtime logic explicitly state the paid/withheld checks are not implemented or executed in this package. This is an active documentation contradiction about what the code does.
The only natural-language content in this manifest-style JSON is entirely in Chinese, including headers and product records, with no indication that the skill supports other languages or that Chinese is an explicitly justified regional requirement. Under the policy, fixed language behavior without user opt-in can be a locale-policy violation.
The comment says non-JSON input is treated as plain-text material such as '直接粘贴的合同全文', which describes contract text rather than food-label ledger material. The actual script and manifest are narrowly about 食品标签与配料表核对, so this inline documentation is contradictory and likely copied from another skill.
No suspicious patterns detected.