Back to skill

Security audit

Shopping Merchant

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk shopping advice skill with one off-topic business-planning example that should be cleaned up but does not create malicious or high-impact behavior.

Before installing, note that this skill is appropriate for shopper-facing merchant trust decisions on Chinese ecommerce platforms. The publisher should remove or split out the night-market food-stall example because it broadens the skill into small-business advice, but the current package is Markdown-only and does not ask for sensitive access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file centers the skill on Chinese ecommerce platforms and all concrete user examples are in Chinese, but it does not explicitly say users may interact in another language or choose their preferred locale. That can amount to an implicit locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes an unrelated scenario about starting a night-market food stall, which materially expands behavior beyond ecommerce merchant-trust evaluation. This can cause an agent to provide business-operational and food-sales guidance in contexts where the skill is expected to stay narrowly scoped, increasing the chance of unsafe or policy-inconsistent outputs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document says the skill is 'not a seller onboarding plan' but then provides concrete seller-startup advice for operating a night-market food stall, including product selection and sourcing. This contradiction weakens scope boundaries and may lead an agent to ignore stated constraints, producing off-domain operational guidance with legal and safety implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

An unrelated usage scenario broadens the apparent scope from purchase-risk evaluation to entrepreneurial stall-planning advice. Scope drift is dangerous because agents often generalize from examples, so one off-topic scenario can override the intended boundaries of the skill and trigger responses in unintended domains.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.