Back to skill

Security audit

芬香返利助手

Security checks for vulnerabilities and agentic risk

Overview

No evidence in the supplied scan context shows deceptive, destructive, or purpose-mismatched behavior.

This looks safe to install based on the available evidence, but review the skill’s own instructions and any requested credentials or commands before running it, especially because VirusTotal had not completed at scan time.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.