Back to skill

Security audit

跨境 Listing 生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a content-generation skill for cross-border e-commerce listings, with no executable code or hidden system access, though some referenced support files are missing.

Installers should treat this as a benign listing-writing helper. Before relying on it operationally, confirm the missing reference files are included in the intended distribution or ask the agent to proceed from current marketplace policies, and review any pricing or compliance output before publishing a live listing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The metadata description embeds many broad trigger phrases such as “生成Listing”, “翻译Listing”, and “Lazada上架”, which can overlap with ordinary multilingual e-commerce requests and cause the skill to activate when the user did not explicitly ask for this workflow. Over-broad activation increases the chance of unintended file loading, user-context hijacking, and incorrect task routing, especially in systems that dispatch skills from natural-language matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are written broadly enough to match general requests like optimization advice, translation, SEO help, or competitor analysis without clear exclusion criteria. In an agent environment, this can lead to mis-triggering on adjacent business tasks, causing the skill to steer the conversation, apply defaults the user did not request, or process sensitive commercial content under the wrong workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

L133-L156 规定“以 Markdown 分块形式清晰呈现”,后续标题字段示例均固定为中文栏目名,如“标题”“五点描述”“产品描述”等,但未明确说明这些栏目语言可随用户偏好切换。对于非中文用户或期望英文工作流的场景,这种默认中文界面文本可能构成语言/locale 约束且缺少显式选择机制。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.