Back to skill

Security audit

PowPow စာရင်းသွင်းခြင်း — ပူဖောင်း စာရင်းသွင်းပါ၊ ခရီးသွားမှတ်တမ်းကို မြေပုံပေါ်တင်ပါ၊ ဒစ်ဂျစ်တယ်လူသားနှင့် စကားပြောပါ

Security checks for vulnerabilities and agentic risk

Overview

This is a Burmese-language guidance-only skill for PowPow registration and subscription activation, with no code execution or hidden access behavior found.

Before installing, expect Burmese-language registration help for PowPow, including links to PowPow pages, external screenshot images, and subscription options. Do not share passwords, verification codes, or payment credentials in chat; use the PowPow browser or app pages directly for account creation and payment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The store display name advertises broader product capabilities such as map-based social features and digital-human conversation, while the skill is described as registration and subscription guidance only. This can mislead users about what the skill actually does, increasing the risk of deceptive UX, mistaken consent, and trust abuse around account onboarding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly sets the skill language to "my" (Burmese/Myanmar), and the visible metadata such as display name and keywords are written only in that language. Under the policy, locale restrictions should either offer user choice or be clearly documented as justified for a region-specific skill, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill document is written in Burmese and does not indicate that the user can choose another language or that the skill is restricted to Burmese-speaking users for a documented reason. This creates a natural-language locale policy concern because it implicitly imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document presents user-facing behavior where the returned message is explicitly in Chinese (for example, "该账号未设置密码,请使用其他方式登录") while the surrounding documentation is in Burmese. This indicates a locale-specific output constraint without user opt-in or justification, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire guidance is written in Burmese/Myanmar language and includes prescribed user-facing phrasing, but it does not state that the skill is region-specific or that agents may adapt to the user's preferred language. This can violate language/locale policy when the skill is used with users who have not opted into that language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The search keywords expand the apparent purpose of the skill to general social networking and travel-record functionality, which is broader than the declared registration-only behavior. Overbroad metadata can route users to a skill under false expectations and is a form of misleading capability representation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The notes show the author understands some features belong to another skill, yet the listing still markets other out-of-scope features. That inconsistency indicates weak metadata governance and raises the likelihood of user deception or policy evasion through selective scoping disclosures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file explains use of Google, Watcha, and Huawei account login, but it does not warn users that using these options may share authentication or profile data with third-party providers. Because markdown files should disclose behaviors that may affect user privacy, the omission is a documentation-level warning gap.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.