Back to skill

Security audit

电商工具箱

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese e-commerce assistant that uses public web research and prompt templates, with recurring monitoring disclosed but worth enabling deliberately.

Install this for Chinese e-commerce workflows where public marketplace research and Chinese copywriting are expected. Before enabling daily or weekly monitoring, confirm what keywords will be searched, where reports will be sent, expected LLM/search costs, and how to stop the schedule. Treat competitor reports as advisory because public search results can influence the generated analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/competitor.js:135
Finding

Untrusted Search Results Embedded Directly into an LLM Prompt

Content
View full analysis
!d.error) .map(([platform, data]) => { const prices = analysisReport.priceRange[platform]; const priceStr = prices ? `价格区间 ¥${prices.min}-${prices.max},中位数 ¥${prices.median}` : '价格数据不足'; const titles = data.results.slice(0, 5).map(r => ` - ${r.title}`).join('\n'); return `【${data.platform}】${priceStr}\n热门商品标题:\n${titles}`; }) .join('\n\n'); const keywordStr = analysisReport.keywords .map(k => `${k.platform}: ${k.topWords.slice(0, 10).map(w => w.word).join('、')}`) .join('\n'); return `你是一个资深电商运营专家。请根据以下竞品数据,为关键词"${keyword}"生成竞品分析报告。 ## 搜索数据 ${platformSummaries} ## 高频关键词 ${keywordStr} ## 请分析以下内容: 1. **市场概况**:这个品类的整体竞争程度、价格带分布 2. **头部竞品分析**:排名靠前的商品有什么共同特点 3. **差异化机会**:从标题和价格中发现的市场空白点 4. **定价建议**:建议的价格区间和定价策略 5. **关键词建议**:标题中应该包含的核心关键词 6. **风险提示**:需要注意的竞争风险 请用简洁的中文回答,适合电商卖家阅读。`; } ``` ### Technical Analysis The `buildAnalysisPrompt` function places external search-result titles into the same text channel as trusted LLM instructions. The values in `data.results[*].title` originate from public web content and may therefore be controlled by an attacker who publishes or manipulates an indexed product page. No trust-boundary delimiters, escaping, instruction filtering, structured-data separation, or explicit instruction-precedence controls are applied before these titles are inserted into the prompt. Consequently, a title containing imperative text can be interpreted by the LLM as an instruction rather than as competitor data. This is an indirect prompt-injection condition. The vulnerability affects the integ ...[truncated 1993 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation examples are broad enough that the agent may trigger this skill for loosely related shopping, product research, copywriting, or monitoring requests without a clear user opt-in boundary. Because the skill performs external searches and can set up recurring monitoring, ambiguous activation increases the risk of unintended data egress, unnecessary browsing, and surprise background actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises automatic web searches, competitor monitoring, cron-based tracking, and push-style daily reports, but does not prominently warn users that their prompts may be sent into external search/fetch workflows or that recurring tasks may persist after the initial interaction. This can lead to unintended disclosure of user business interests and surprise ongoing actions, which is especially risky in a commerce context where product strategy and market research may be sensitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt text is written to instruct the model as a Chinese e-commerce operator and implicitly requires Chinese output. This is a natural-language locale policy issue because the skill does not provide any opt-in or alternative language selection for users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The detail, Xiaohongshu note, live script, and customer service templates all prescribe Chinese-language, China-platform-specific copywriting styles with no option for the user to select another language or locale. Because this file applies the constraint across templates, it constitutes a repeated natural-language policy violation rather than a single isolated string.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This prompt hard-codes a '全平台电商运营专家' role and generates content for Chinese platforms such as 淘宝, 拼多多, 小红书, 抖音, and 1688, implying Chinese-language output by default. There is no documented opt-in, fallback, or language selection, so the locale is forced rather than chosen by the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt explicitly instructs the model to respond in Chinese ("用简洁的中文回答") with no indication that the user can choose another language. This is a natural-language locale policy concern because it hard-codes a language preference rather than offering opt-in or documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt formats the date using the zh-CN locale and instructs the model to generate the report in Chinese-style wording, without presenting this as a user choice. This enforces a specific language/locale and fits the policy-violation category for locale restrictions without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file embeds Chinese-language queries, comments, and user-facing return strings such as search phrases and price/status text, and it also fixes scheduling to the Asia/Shanghai timezone. The skill does not indicate any user opt-in or configurable language/locale selection, which matches the policy concern for forcing a specific language/locale without choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description recommends pairing the skill with "chinese-llm-router" and domestic models for better results, which implicitly steers users toward a Chinese-language/localized setup. The file does not present this as an optional user language choice or explain a necessary region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire cheatsheet is written in Chinese and presents fixed Chinese-language templates for titles and customer-service scripts, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill is expected to be language-neutral unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt hard-codes '请用简洁的中文回答', forcing Chinese output regardless of the user's language preference or downstream system expectations. This is a real but low-severity prompt-quality/security issue because it can override user intent, reduce transparency, and cause incorrect or unusable outputs in multilingual contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function comment at L039-L043 introduces a selection-analysis prompt generator, matching buildSelectionPrompt. However, the same module also includes buildDailyReportPrompt at L123-L143 for 竞品监控日报, which is a different monitoring/reporting function than product selection analysis. This is an intent/documentation divergence within the file documentation scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.