Back to skill

Security audit

Omni Ecom Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese e-commerce advisory skill with no executable code, persistence, credential handling, or hidden data movement found.

Install if you want Chinese-language e-commerce operations analysis for platforms such as Tmall, JD, Pinduoduo, Douyin, WeChat Channels, and Xiaohongshu. Be aware that it may default to Chinese and may trigger on broad business-plan phrasing; provide only the business reports and platform data you intend the assistant to analyze.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is entirely written as a Chinese-only skill persona and scope statement, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction on output language/style requires a specific professional register tailored to Chinese-brand-owner and operations-team readers, but does not offer an alternative language or opt-in. This can be interpreted as mandating a locale/language mode rather than adapting to user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest presents the display name, description, and category entirely in Chinese, which implies a fixed language experience without indicating user opt-in or a documented locale constraint. Under the policy, language restrictions should either provide user choice or be explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase at line 13 ("经营方案") is broad and can match many generic business-assistance requests outside the narrowly intended e-commerce diagnostic scope. This can cause unintended skill invocation, leading to prompt hijacking of unrelated requests, user confusion, or bypass of more appropriate skills, though it does not by itself enable code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hard-codes a Chinese persona/output style (e.g., a named Chinese expert identity and Chinese-only reporting conventions) without indicating that the user can choose another language. This can override user preference, reduce accessibility, and cause unintended disclosure or miscommunication in multilingual environments, though it is not directly a code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill specification is written as a Chinese-only persona and workflow, with no indication that users may choose another language or that the skill is restricted to a Chinese-language or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill definition is entirely in Chinese and assigns a fixed Chinese expert identity/output style without indicating any user language preference, opt-in, or fallback behavior. This can cause unintended exclusion, misalignment with user intent, or unsafe misunderstanding if a user expects another language, though it is not a direct code-execution or data-exfiltration risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes that all outputs must be in Chinese regardless of the user's language preference. This can override user intent, reduce transparency for non-Chinese-speaking users, and create a prompt-level policy conflict that may be abused to hide important warnings or degrade safe operation in multilingual contexts. In this e-commerce advisory context it is not directly a code-execution risk, but it is still a real safety and usability issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file is entirely written as a Chinese-language persona and output specification, including a fixed Chinese identity and Chinese formatting conventions, but it does not indicate that the user can choose another language. Under the policy for natural-language violations, a forced language or locale without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction "语言专业直接" appears in a Chinese-language skill document and constrains output language/style without any opt-in or alternative language choice for the user. Under the policy, forcing a specific language or locale without user choice can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.