Back to skill

Security audit

Agent Services Cn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a static Chinese-language guide for AI agent services and pricing, with no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install only if you want a static Chinese-language reference for agent service categories, prices, suggested agents, and promotion templates. Treat the listings and prices as author-curated guidance rather than verified marketplace data, especially where the author recommends their own services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is an 'Agent Services Marketplace' for finding AI agents. However, the supplied code does not implement any marketplace or discovery behavior. It is a simple shell script that outputs a static service pricing guide in Chinese, covering pricing considerations, fee models, strategy tiers, example rates, and payment options. There are no triggers, permissions, or hidden resource accesses, but the primary purpose is materially different from the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description suggests a service marketplace where users can find AI agents for various tasks. The supplied code does not provide marketplace, search, listing, matching, or discovery functionality. Instead, it is a simple shell script that outputs a template for agents to advertise their services and recommends channels for posting those ads. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README describes the skill in very broad terms as helping users 'navigate the agent-to-agent service marketplace' with no explicit trigger phrases, scope boundaries, or exclusion conditions. In a markdown skill description, this kind of open-ended activation language can overlap with many generic marketplace, pricing, research, or services-related requests and makes it unclear when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents all user-facing messages in Chinese, including usage, categories, and recommendations. Because it does not offer any language selection or document a justified locale restriction, it violates the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The feature list includes 'China/Localization (Chinese market insights),' which introduces a locale-specific focus in the skill description. Because the README does not state that this locale specialization is optional or user-selected, it may violate language/locale policy expectations requiring opt-in or clear justification for region-specific behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script's comments and all echoed instructional content are presented only in Chinese, which imposes a specific language on users. Under the policy, locale or language restrictions should either provide user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script presents all user-facing instructions and template text in Chinese only. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or choice is offered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.