Back to skill

Security audit

Qstar Video Ecom

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese e-commerce video-generation workflow, with privacy and marketing-claim risks users should manage before using it.

Install this only if you intend to use Qstar/Guanma for Chinese e-commerce video generation. Do not submit confidential product images, private URLs, sensitive business details, or unnecessary contact information unless you are comfortable sending them to the external service. Review and edit generated scripts carefully, especially for food, cosmetics, supplements, baby products, elder-care products, or any health/safety claims, because the templates may overstate benefits or guarantees.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template library repeatedly encourages strong efficacy, safety, medical-adjacent, and quality assurances such as '质量绝对有保障', '安全第一', '可以放心用', ingredient efficacy, and quantified performance claims without requiring substantiation, disclaimers, or category-specific restrictions. In an AI content-generation skill for e-commerce videos, this can systematically produce deceptive or non-compliant marketing for cosmetics, food, maternal/infant products, supplements, and products targeting elderly users, increasing legal, consumer-safety, and platform enforcement risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses a broad natural-language invocation phrase ('generate or revise a Chinese e-commerce short video for my product') that can match many ordinary user requests. Because implicit invocation is enabled, the skill may be triggered unintentionally for generic product-video tasks, causing overbroad routing and unexpected tool use.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill metadata and default prompt hard-code Chinese-language output without indicating user choice or consent. This can lead to misaligned outputs, accidental invocation in the wrong language context, and reduced user control, especially when combined with implicit invocation.

Static analysis

No suspicious patterns detected.