Back to skill

Security audit

ShopGuard

Security checks for vulnerabilities and agentic risk

Overview

ShopGuard is a non-executable shopping-risk guidance skill that is coherent with its stated purpose and includes clear limits against account access or checkout actions.

Installers should treat this as a shopping-risk advice skill, not an automated buying assistant. It may inspect public listing information and give direct go/no-go recommendations, but it should not log into accounts, message sellers, place orders, or enter checkout without separate explicit user direction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
- keep confirmed facts separate from directional inferences

Stop before:
- logging into the user's account without consent
- chatting with sellers
- placing an order
- entering irreversible checkout steps

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt is broadly phrased and encourages open-ended invocation of the skill without clear boundaries on when it should activate. In an agent ecosystem, this can increase the chance of over-triggering, unintended routing, or the skill being applied to loosely related shopping queries where its guidance may be unreliable or manipulable by surrounding context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The short prompts are extremely generic phrases such as 'Can I buy from this seller?' and 'Is this route safe enough?' that closely match ordinary user language. In an agent routing system, this can cause the skill to trigger on broad shopping or trust questions outside its intended scope, leading to over-activation, misrouting, and potentially unsafe advice being applied without sufficient platform- or evidence-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The platform heuristics explicitly target Chinese e-commerce platforms and use locale-specific marketplace assumptions, but the document does not state that it is intended only for that region or ask the user to opt into that locale context. Under the policy, forcing a specific language/locale context without opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.