Back to skill

Security audit

收货总管

Security checks for vulnerabilities and agentic risk

Overview

OrderKeeper is a disclosed Chinese/mainland-China post-purchase support skill with no executable code; the main consideration is that it may handle private order and receipt details.

Install this if you want Chinese-language help organizing post-purchase order problems. Avoid sharing unnecessary personal data in screenshots or receipts, and review any generated customer-service message before sending it, especially if you prefer a language other than Chinese.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is entirely in Chinese and all example prompts are Chinese-language invocations, which signals a fixed language/locale expectation. There is no statement that other languages are supported, no opt-in for Chinese, and no justification that this is a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content is predominantly written in Chinese and presents the skill copy, titles, and user-facing descriptions in a single language without offering an alternative language or stating that the skill is region- or locale-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly requires the customer-service script to be in concise, sendable Chinese without offering a language fallback or documenting that the constraint is limited to mainland China support interactions. This can exclude users who need another language or accessibility accommodation, and may cause incorrect or unusable outputs if the user is not able to review or send Chinese text safely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default prompt invokes the skill through a broad, catch-all instruction without defining tighter trigger conditions or scope boundaries. This increases the chance the agent will route unrelated conversations containing order-like language into the skill, causing unintended handling of purchase, refund, or warranty decisions and unnecessary exposure of potentially sensitive order information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Forcing Chinese output in the default prompt overrides user language preference and can degrade comprehension when the user is not expecting or able to read Chinese. In an after-sales context, misunderstanding deadlines, refund steps, or warranty instructions could lead to missed actions or incorrect decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tone rule explicitly prefers the Chinese phrase 现在先做这个, which imposes a language choice in the skill guidance without indicating that the user can choose their preferred language. This is a natural-language policy concern because it can cause responses in a specific locale regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains all customer-service script frames exclusively in Chinese across multiple sections, but it does not state that the skill is intended only for Chinese-speaking contexts or offer the user a language choice. That can violate the language/locale policy because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language shopping assistant without offering any language or locale choice. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Useful phrasing' section provides only Chinese example text, which can imply the skill expects or enforces a specific language. Because the document does not offer an alternative language option or explain that it is intended for a Chinese-language context, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.