Back to skill

Security audit

smart-cart-integration-troubleshooter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a hardware troubleshooting guide with a small local checklist script; the main caveat is that it uses Chinese report headings without clearly declaring that locale choice.

Installers should expect this skill to produce reports with Chinese section labels unless they edit or override the template. For hardware use, follow the included safety stops and verify missing controller, port, protocol, and calibration details from trusted project documentation before testing a real cart.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The output template requires section headings in Chinese (`故障现象`, `已确认事实`, etc.), which forces a specific language for responses. The file does not provide any user opt-in, alternative language option, or explanation that the skill is intended only for a Chinese-language context.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file contains all user-facing instructions in Chinese, which can amount to forcing a specific language on users without opt-in. The policy allows locale constraints only when they are explicitly offered as a choice or clearly documented as region-specific, neither of which appears here.

Static analysis

No suspicious patterns detected.