Back to skill

Security audit

package design包装设计&改进

Security checks for vulnerabilities and agentic risk

Overview

This skill is a packaging-design helper with local calculations, reference checklists, and disclosed web-search guidance; I found no hidden, destructive, or credential-seeking behavior.

Before installing, treat this as a Chinese-market packaging reference and estimation aid. Verify current regulations and engineering calculations with authoritative sources or qualified reviewers before using outputs for production packaging, labeling, or compliance decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

描述强调三类核心能力:包装方案设计、材料选择、法规审核。其中代码只覆盖了部分与包装相关的工程计算辅助功能,如成本、尺寸、阻隔和收缩率估算,以及简单材料成本比较。这与“包装设计能力”有一定相关性,但对“法规审核”这一明确声明的能力完全没有实现;“包装方案设计”也没有生成设计方案、校核结构、标签、工艺或合规约束;“材料选择”仅体现为基于输入参数的简单比较和阻隔建议,范围明显窄于声明。因此该技能描述高估了代码实际能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and operational instructions are entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale guidance. The policy allows locale constraints only when explicitly optional or clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that assume Chinese as the only supported language, beginning with the module docstring and continuing throughout the CLI help text. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown guide presents all user-facing content only in Chinese and does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L101 states '使用规范汉字' and treats '繁体字' as a violation. This imposes a specific language/script policy in natural language without indicating that the checklist is limited to a Mainland China regulatory context or that alternative locale handling is allowed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.