Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a legitimate Chinese e-commerce toolkit, but its live-data workflow can turn untrusted JSON values into executable shell command text without validation or quoting.
Review before installing. The calculators themselves look ordinary, but do not execute live.py generated commands from untrusted or web-derived live_data.json without validating and shell-quoting every value. Treat live WebSearch/WebFetch mode as sending business-sensitive product, pricing, supplier, and platform terms to external sites.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The description presents a comprehensive multi-tool e-commerce operations skill with live data integration across multiple platforms. The actual code chunk is much narrower: it is a single ad ROI/CPC calculator script. While this script does align with one subset of the declared functionality—广告投放ROI测算—it does not implement the majority of the described capabilities, especially the real-time data bridge and the other six calculators/tools. There is no network access, no compliance checking, no title generation, no inventory planning, and no funnel diagnosis in the provided code. Therefore the supplied code does not accurately represent the declared overall skill behavior, making this a material description-behavior mismatch.
The code chunk is narrowly focused on one sub-capability mentioned in the description: advertising/compliance term checking for e-commerce copy. That part is aligned. However, the declared purpose presents the skill as a comprehensive e-commerce operations suite with multiple calculators and a real-time data connector, while this code provides none of those functions. There is no network access, no web search/fetch integration, no platform-specific operational logic, no pricing/profit/ROI/funnel/inventory computation, and no title generation. Therefore the supplied code materially underdelivers relative to the declared description, making the description inaccurate for this code chunk.
The declared description presents a broad, action-oriented e-commerce operations toolkit with multiple analytical calculators and live market-data ingestion. The actual code chunk does not implement those capabilities. It only defines static fee references for several platforms and some generic benchmark ranges, with simple formatting/access utilities. While static platform fee data could support a larger pricing/profit tool, this chunk by itself is much narrower in purpose and lacks the claimed live fetching, computation, compliance checking, title generation, and inventory planning behavior. Therefore the description materially overstates what this code chunk actually does.
The skill is presented entirely as a Chinese-language "国内电商" skill and does not mention any user language choice or opt-in behavior. While the domain is China e-commerce, the file does not explicitly state that the locale restriction is intentional and region-specific, which can create a language/locale policy concern under the stated rules.
The README describes automatic triggering but does not clearly define when the skill should not activate, especially for adjacent topics like general copywriting, platform advice, or broad e-commerce strategy. Ambiguous activation boundaries increase the chance of overreach: the agent may invoke calculators or live-data workflows when the user only wanted discussion, causing incorrect assumptions, extra external fetches, or confusion about the source of answers.
The README describes automatic triggering but does not clearly define when the skill should not activate, especially for adjacent topics like general copywriting, platform advice, or broad e-commerce strategy. Ambiguous activation boundaries increase the chance of overreach: the agent may invoke calculators or live-data workflows when the user only wanted discussion, causing incorrect assumptions, extra external fetches, or confusion about the source of answers.
The skill explicitly directs use of WebSearch/WebFetch and executable Python scripts, but the manifest does not declare any tool scope, permissions, or allowed-tools restrictions. This creates an overbroad capability surface where the runtime may grant file, shell, and network access without user-visible least-privilege boundaries, increasing the chance of unintended data access or outbound requests.
The skill repeatedly instructs the agent to use WebSearch/WebFetch to retrieve live commission rates, return rates, supplier pricing, and keyword volumes, but it does not clearly warn that user queries and business parameters may be transmitted to third-party sites. This can expose commercially sensitive product ideas, pricing assumptions, platform strategy, or supplier interests to external services without informed consent.
The trigger list includes broad, common business phrases, which can cause the skill to activate for loosely related conversations. In a skill that encourages network fetching of live data and use of calculation scripts, accidental invocation can lead to unnecessary external requests, data exposure of user business context, or over-application of the skill outside intended scope.
This markdown file contains user-facing guidance solely in Chinese, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the natural-language policy rule, forcing a specific language without opt-in is a policy concern.
The file begins with a Chinese-only title and the entire playbook is written in Chinese, with no indication that language selection is optional or that the skill is intended solely for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
This code file contains natural-language instructions, descriptions, and warnings exclusively in Chinese, and the CLI/help text and rendered report are likewise fixed to Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in is a natural-language policy violation.
This Python file contains user-facing natural-language documentation entirely in Chinese and presents the tool as a Chinese-language skill, with no indication that users may select another language. The policy for this audit flags language or locale constraints when they are imposed without opt-in or justification.
The module docstring and all user-facing CLI messages are written in Chinese, establishing a fixed language for interaction. For a general-purpose inventory calculator, this is a natural-language locale constraint without any documented opt-in, fallback, or user-selectable language behavior.
The module docstring, command descriptions, and user-facing output are entirely in Chinese, effectively imposing a specific language/locale on all users. The file does not offer any opt-in, alternative locale, or explicit justification that this skill is intended only for a Chinese-speaking or region-specific audience.
This code file contains user-facing natural language entirely in Chinese, including the module description and CLI help text, which effectively enforces a specific language for all users. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified; neither is present here.
This Python file contains its primary documentation and runtime status messages entirely in Chinese, including usage instructions and pass/fail summaries. That imposes a specific language on users without any visible opt-in or alternate locale handling, which matches the language/locale policy violation criteria.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(args: list[str], cwd: str = SCRIPTS):
"""执行子进程,返回 (returncode, stdout+stderr)。"""
p = subprocess.run(
[PY] + args, cwd=cwd, capture_output=True,
text=True, encoding="utf-8", errors="replace",
)
描述以“国内电商全链路运营专家技能”为定位,全文默认使用中文平台语境与中文文案场景,且未说明是否支持其他语言或允许用户自行选择输出语言。按照语言/locale 政策,若技能对语言环境作出默认强约束而无选择机制,属于自然语言层面的潜在策略问题。
The natural-language note is entirely in Chinese and assumes use of China-specific platforms and tooling references such as 抖店规则中心、1688、义乌购、巨量算数、生意参谋. For a general-purpose skill/config file, this creates a locale-specific constraint without any stated user opt-in or documented justification in the file.
SQP-3 applies to all file types and covers language or locale policy violations. This skill content forces a specific language for all instructions, and the file does not offer user opt-in or explain that it is intentionally limited to a Chinese-language or region-specific audience.
This Python skill hard-codes its natural-language interface entirely in Chinese, including the module description, CLI help text, errors, and rendered report output. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.
This code file contains natural-language documentation, help text, error messages, and output labels exclusively in Chinese. Under the language/locale policy, forcing a single language without user opt-in can be a policy violation when no alternative locale or language selection is provided.
No suspicious patterns detected.