Back to skill

Security audit

Pans Upsell Radar

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local sales upsell-analysis helper with disclosed customer-data files and no evidence of hidden network access, credential use, or destructive behavior.

Install only if you are comfortable storing customer and opportunity data locally under ~/.qclaw. Replace or review the bundled sample customer data, avoid running broad scans on confidential customer lists without authorization, and prefer explicit commands over broad trigger phrases.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include broad business terms such as "upsell", "交叉销售", and "客户增长", which are likely to appear in ordinary sales discussions unrelated to this tool. Overbroad triggers can cause unintended invocation, leading the agent to scan customers or expose opportunity analysis in contexts where the user did not intend to run the skill.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The usage examples and storage section describe bulk customer scanning and local persistence of customer, signal, and opportunity data, but the skill provides no warning about privacy, data handling, or the scope of analysis. In a sales context, this increases the risk of processing sensitive commercial information without informed user consent or proper safeguards.

Static analysis

No suspicious patterns detected.