Back to skill

Security audit

YHD

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed 1号店 shopping helper that can use browser automation for search and cart preparation, but it tells the agent to keep payment and final order submission under user control.

Install only if you want an agent to help with live 1号店 shopping. Before allowing cart or order-preview steps, confirm the selected products, quantity, account/session use, address, coupon changes, and delivery slot; complete payment yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises an operational shopping skill for 1号店, including browser automation and user-account/cart-related workflows. The supplied code does not implement any of that. It contains only hardcoded timing/category/membership data and small utility functions that compute current/next sale windows and membership suggestions. While the general topic area (YHD shopping advice, flash sales, fresh grocery guidance, membership benefits) overlaps, the actual behavior is limited to static informational guidance rather than executing shopping tasks. This is a material description-behavior mismatch because the primary purpose and capabilities are substantially overstated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The feature description promotes browser automation, cart operations, coupons, delivery-slot selection, and order preview, but does not explicitly warn that these actions rely on an authenticated session and can modify a real shopping cart. In a logged-in retail environment, omission of this warning increases the risk of unintended state-changing actions and user surprise about account-scoped behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation example '帮我买1号店的牛奶' is broad enough to match ordinary shopping requests without clearly signaling that the skill may use browser automation on a live logged-in retail session. This can cause the agent to act in a real commerce context, including modifying a cart or progressing toward an order preview, when the user may have intended only advice or price comparison.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 351)May include surrounding context.

md
### Do Not:
- ❌ Pretend to log in (ask first)
- ❌ Claim to confirm live inventory without checking
- ❌ Store user data persistently
- ❌ **Execute payment or final order submission**
- ❌ Guarantee flash sale availability

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The execution guide and required pre-action announcements are written as fixed Chinese phrases for user-facing interaction, and the document does not indicate that the agent should adapt to the user's preferred language. This can violate a language/locale policy when a skill imposes one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language strings describe the skill specifically as 'Shop 1号店' and 'YHD.com (1号店)', which anchors the experience to a Chinese-language/regional context without any visible opt-in or alternative locale handling. Under the policy rule, a forced language/locale experience should either offer user choice or clearly justify the locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes an automation-focused skill for searching YHD, browsing while logged in, adding items to cart, and previewing orders. In this file, the implementation is limited to hardcoded flash-sale timing, membership tiers, grocery tips, and time-based helper functions, with no browser automation, site interaction, or cart/order handling logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is written entirely in Chinese and presents the skill as a Chinese-language shopping assistant without stating that language selection is optional. Under the language/locale policy rule, this can be a natural-language policy concern because it implies a fixed language experience with no documented opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.