Back to skill

Security audit

Rent Computer Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent computer-rental workflow, but it can turn vague performance complaints into a vendor rental flow and send address/contact details without a clear final consent step.

Review before installing. Only use this skill when users explicitly ask to rent a computer or GPU server, and add a confirmation step that shows the destination, address, contact method, and message before submitting anything. Users should be told that their details will be sent to zhiweisoft.com and should avoid including unrelated sensitive information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:7
Finding

Broad Trigger Conditions Redirect General Performance Complaints into Vendor Promotion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:58
Finding

Personal Address and Contact Details Are Submitted Without Explicit Final Consent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks for sensitive personal data, including address and contact details, and sends it to a third-party endpoint without any visible privacy notice, purpose limitation, consent language, retention policy, or trust verification. In the context of a rental workflow, this is especially dangerous because broad triggers may first misclassify a casual support request, then escalate into collecting and transmitting personally identifiable information to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill will automatically trigger when users complain about poor computer performance or mention needing stronger hardware, which are common and ambiguous help-seeking statements. In a transactional skill, broad triggers can cause the agent to steer ordinary troubleshooting conversations into a real-world rental flow without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes automatically collecting shipping address and contact details and then automatically submitting a rental application, but it does not mention any explicit consent, privacy notice, or confirmation before the consequential action. Because this involves personal data and a real-world order, silent progression from chat to transaction creates substantial privacy and unauthorized-action risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The feature list presents address collection, contact collection, and automatic order submission as normal behavior without warning that these actions affect privacy and may create a real rental transaction. In a skill that can be auto-triggered, omitting this warning makes accidental disclosure and unintended commitments more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed scenarios include broad conditions like 'computer too laggy' or 'can't run AI/models,' which overlap with common technical support requests rather than a clear request to rent equipment. This increases the risk of unintended activation and inappropriate escalation into collecting personal information or initiating a commercial transaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to activate on common complaints like '电脑太卡了' or '电脑抱怨卡', which can cause the agent to steer ordinary troubleshooting conversations into a rental workflow. This creates a consent and integrity problem: users may be funneled toward a commercial action without clearly expressing rental intent, increasing the chance of unintended data collection and external API use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The entire skill description and trigger behavior are presented only in Chinese, with no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.