Back to skill

Security audit

零售渠道与竞对分析专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped retail analytics helper that calls disclosed APIs with a user-provided key and does not add hidden execution, persistence, or unrelated data access.

Install only if you intend to use the gotoshop-ai retail data API. Keep the DDT_API_KEY private, verify the DDT_OPEN_BASE endpoint before use, and expect the skill to send retail brand, coordinate, or public store-ID queries to that service when you ask for those analyses.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:27