Back to skill

Security audit

识货购物助手

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Chinese shopping guidance skill with no code, credential use, persistence, or hidden system access.

Install only if you want a Chinese shopping assistant for authenticity checks, price comparison, coupons, and rebate calculations. Treat prices, authenticity advice, coupon availability, and cashback terms as guidance and verify details directly on the shopping platform before buying.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad terms like '正品鉴别' and '运动鞋比价' that can match generic shopping or product-advice requests beyond the intended branded skill scope. This increases the chance of over-invocation, causing the assistant to route unrelated commerce queries into a domain-specific skill and potentially produce misleading or unwanted shopping guidance.

Static analysis

No suspicious patterns detected.