Back to skill

Security audit

Buying

Security checks for vulnerabilities and agentic risk

Overview

This skill provides disclosed shopping-comparison advice and does not include hidden code execution, account access, payment actions, or persistence.

Install this if you want a China-market shopping comparison advisor. Treat its output as advice, verify live prices and seller details yourself before buying, and do not provide account credentials or authorize it to place orders or send payment details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README is written entirely in Chinese, including the title, description, and all example interactions, with no indication that other languages are supported or that Chinese is optional. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable locale/language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction 'Sound like a decisive Chinese internet shopping advisor' imposes a specific language/locale presentation on all outputs. The file does not offer the user any language or locale choice or indicate that this constraint is optional or region-specific.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
- mark any assumptions clearly

Stop before:
- logging into the user's account without consent
- claiming access to private order history
- placing irreversible orders
- sending purchase messages or payment details

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a cross-platform buying decision skill for comparing the same product across marketplaces and outputting an optimal purchase path. In Scenario 2, the skill is documented as providing a general Double 11 shopping playbook, including historical price tracking via third-party apps, cart management, presale deposit tactics, and broad deal-hunting strategy, which goes beyond same-product cross-platform comparison.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt advertises a broad invocation phrase ('Use $buying to compare...') without any trigger constraints, scoping rules, or guardrails about when the skill should activate. In an agent environment, this can cause over-invocation or prompt-surface expansion, increasing the chance the skill is called in unintended contexts and influences buying recommendations without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description states the skill will '输出最优购买路径' and is written entirely in Chinese, indicating a Chinese-language interaction model without any mention of user language choice. This can violate language/locale policy guidance when a skill appears generally applicable but implicitly enforces one language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction 'Use this file when the user wants a recommended route rather than a raw winner' does not define clear trigger phrases, scope boundaries, or negative examples. This leaves substantial ambiguity about when the skill should activate versus when another purchasing-comparison behavior should be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file instructs the model to prefer Chinese output phrases regardless of the user's language, which can override user preference and system-level localization expectations. While this is not a direct code-execution or data-theft issue, it is a prompt-control weakness: embedded content is steering output format in a way that may conflict with higher-priority instructions and degrade safe, reliable behavior across users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The short description is written in Chinese while the default prompt is in English, which implies a language choice has been made by the skill rather than the user. The file does not state that the user can choose their preferred language or that this mixed-language behavior is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file consists entirely of Chinese example prompts and does not indicate that language choice is optional or configurable. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.