Back to skill

Security audit

Safety Footwear Buyer Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, static buyer-assistance tool with disclosed supplier references and no evidence of hidden transmission, persistence, or privileged behavior.

Before relying on this for procurement, treat its supplier pages and product matches as examples only. Verify certifications, company identity, quotation terms, samples, and live contact details directly with the supplier before ordering.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill promises supplier verification, RFQ preparation, and a purely local mock inquiry flow, but the documented behavior appears to provide hardcoded live supplier links while not actually performing meaningful verification or full RFQ drafting. This can mislead business users into treating marketing content or minimal validation as due diligence, creating procurement, trust, and social-engineering risk even without direct code execution or data exfiltration.

Static analysis

No suspicious patterns detected.