Security audit
Tmall Weekly Report
Security checks for vulnerabilities and agentic risk
Overview
This skill appears to locally generate a Tmall weekly business report and charts from user-provided operating data, without hidden network access, credential use, persistence, or destructive behavior.
Before installing, understand that this skill is intended for sensitive store operating data and produces local report artifacts. Review and replace the hardcoded sample data and absolute chart output path in the script so reports are generated in the intended workspace and do not mix old client data with new reports.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
