Back to skill

Security audit

Freshippo

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed grocery-shopping decision assistant, but it under-scopes use of an already logged-in browser session for a shopping account.

Install only if you are comfortable with a read-only shopping assistant. Avoid letting it operate inside a logged-in Freshippo browser session unless you have explicitly asked for that and are watching what pages it opens; keep address, coupons, cart changes, delivery-slot reservation, checkout, and payment manual.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims a safe decision-assist boundary, but later permits operation inside an already logged-in browser session. Even without performing the login step itself, acting within an authenticated context can expose account-specific data and increases the chance the agent will drift into account-affecting actions such as viewing addresses, delivery slots, coupons, or shopping cart state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The execution guide hard-codes Chinese prompts and user-facing announcements such as "正在搜索..." and the sample invocation pattern is entirely Chinese. This imposes a specific language/locale on user interaction without documenting an opt-in or offering alternatives, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation contains conflicting rules: one section says not to log in or claim to be logged in, while another authorizes proceeding when a browser profile already has an active session. This ambiguity weakens operator safety boundaries and can lead the agent to treat authenticated account access as acceptable, increasing the risk of privacy exposure and unintended state-changing behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
### Do Not:
- ❌ Log in or claim to be logged in
- ❌ Claim to confirm live inventory without checking
- ❌ Store user data persistently
- ❌ Change the user's in-app product list, apply coupons, reserve delivery slots, or choose addresses
- ❌ **Execute payment or final order submission**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is entirely in Chinese and presents the skill as a Chinese-language shopping assistant without any indication that users can choose another language or locale. This can violate language/locale policy when a skill appears to impose a specific language by default rather than offering user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The sample output makes definitive claims about freshness and delivery-slot quality that may be interpreted as live, verified conditions. In a shopping assistant, overstating certainty can mislead users into relying on stale or unverified operational data, especially for perishable goods and time-sensitive delivery planning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.