Back to skill

Security audit

UUMit自动接单机器人

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware, but it asks the agent to automatically apply for paid UUMit tasks and handle USDT billing with too little user control or credential guidance.

Review this carefully before installing. Only use it with a limited-scope UUMit API key, clear spending limits, and manual confirmation before applications or payments. Do not enable unattended auto-apply or automatic USDT settlement unless you understand how to stop it and revoke access.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises automatic scanning, matching, and submission using a configured UUMit API key, but it provides no warning about the risks of automated submissions, account actions, billing, or secure handling of credentials. This can mislead users into enabling unattended actions and exposing API keys without understanding the operational and security consequences.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description advertises automatic scanning and applying behavior but does not define clear activation boundaries, user consent requirements, or trigger constraints. In an automation skill that can initiate actions on external platforms, ambiguous scope increases the risk of unintended autonomous behavior, excessive requests, or actions taken without explicit user approval.

Static analysis

No suspicious patterns detected.