Back to skill

Security audit

补货参谋

Security checks for vulnerabilities and agentic risk

Overview

PantryPilot is a coherent shopping-planning skill that gives replenishment advice without asking to log in, buy items, or take irreversible commerce actions.

Install only if you want a China-market replenishment planner. Provide household inventory, menus, screenshots, or order history only when you are comfortable sharing that context, and keep checkout, payment, coupons, and account-only data under your own control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about end-user replenishment planning functionality, but the actual code chunk does not implement any pantry analysis, demand estimation, shopping-platform routing, or restock-plan generation. Instead, it is purely a deployment/publishing script for distributing the skill package. While such tooling can support the project, this code's primary behavior is materially different from the declared skill purpose, so this chunk is a mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples are broad, natural-language shopping requests such as '帮我看看这周家里该补什么', which overlap heavily with ordinary conversation and can cause the skill to activate in situations the user did not explicitly intend. In a commerce-related skill, unintended invocation can expose household inventory, menu, purchase-history, or shopping-planning context to the skill and lead to privacy leakage or unwanted agent actions/recommendations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The release notes specify Chinese-only alternate title and short description text, and the publish command later sets the skill name to Chinese, but there is no indication that language selection is optional or limited to a Chinese-speaking marketplace. This can violate language/locale policy because the skill presentation appears to enforce a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states the skill is for 'mainland China,' and the document then presents core user prompts and phrasing primarily in Chinese without saying the user can choose another language or locale. This creates a natural-language locale constraint that is not framed as optional or explicitly justified as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt hard-codes that recommendations should be produced in Chinese regardless of the user's language preference or explicit opt-in. This can reduce transparency and user comprehension, increasing the chance that users misunderstand purchasing recommendations, pricing, substitutions, or delivery constraints, though it is not a direct code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description forces a single language presentation and does not indicate that users may choose another language or locale. This can violate language-choice policy when a skill is not clearly documented as region-specific or explicitly opt-in for that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains only Chinese-language example prompts for invoking the skill, which effectively forces a specific language/locale for users reading or copying the examples. The file does not indicate that the skill is China-specific or that other languages are supported, so it creates a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown reference includes natural-language examples only in Chinese for user statements, which can steer the skill toward a specific language behavior. Because the file does not provide an opt-in language choice or explain that the skill is intentionally Chinese-language or region-specific, it presents a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The fast-answer shortcut lists only Chinese output phrases, which can cause the skill to answer in a fixed language regardless of the user's preferred locale. The file does not state that responses should match user language or that Chinese output is optional, so this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest describes the skill's purpose in broad product terms, but it does not specify how or when the skill should be invoked, nor any boundaries or exclusion conditions. In manifest files, missing trigger specificity can lead to unintended activation if downstream systems infer invocation from generic shopping or replenishment-related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document defines routing shortcuts exclusively with Chinese phrases like 今晚缺口 and 这周鲜食, which imposes a specific language/locale in the skill guidance. There is no indication that users may use another language or that the locale restriction is intentional and documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.