Back to skill

Security audit

中国3C营销助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed China-market 3C marketing assistant, and I found no hidden persistence, credential use, destructive behavior, or remote code execution.

Install this if you want Chinese China-market consumer-electronics marketing assistance. Expect it to influence strategy and launch/risk decisions, so verify current prices, rankings, product specs, KOL status, and platform trends before using outputs for real campaigns. Avoid feeding confidential comment exports or business data unless that is intended for the analysis task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (103)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个营销策略技能包,重点在帮助3C新品营销从创意到执行、预警和复盘;而代码实际是一个CLI校验器,核心功能是检查文档是否符合 audience layering(前台/后台内容分层)规范,以及模板文件是否包含特定政策术语。它不体现任何与手机、电脑、耳机、穿戴、智能家居营销策略制定相关的业务逻辑,也不进行创意生成、渠道规划、竞品分析、评论区压力测试或负面预警判断。其主要目的与能力均与声明严重不符,因此应判定为明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个覆盖3C新品营销全流程的策略技能包,能力范围很广,偏向策划、执行辅助、风险预警和复盘。实际代码却非常单一:验证一个“decision package”样本文件的结构与内容,并对输入文本按关键词规则判断评审状态。虽然“上线判断/评审状态”与声明中的部分场景存在弱相关,但这段代码的主要目的并不是营销策略支持,而是特定决策包数据集校验与状态分类,能力范围远小于且不同于声明内容,因此构成明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个覆盖中国3C新品营销多个环节的综合策略技能包,范围很广,且强调从创意到执行、避雷、复盘的营销支持能力。实际代码却是一个单一用途的评测/校验脚本:先读取本地 executive-memo-samples.json,再校验样本结构与预期分类,并可对输入文本做基于关键词的三分类判断。它确实与“上线判断/是否执行”这一很窄的决策场景有弱相关,但整体主用途明显不同,且没有实现大部分已声明的营销能力。因此描述不能准确代表该代码实际行为,属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的中国3C新品营销策略工具,覆盖创意、渠道、洞察、预警、上线判断和复盘等业务能力。实际代码仅是一个用于“freshness claims”检查的 CLI 脚本:先验证样本文件结构,再根据若干高时效词/稳定词对单条文本做简单分类并打印标记。虽然其中包含“新品”“KOL”等词,和营销场景有轻微表面关联,但代码的主要目的与描述相差很大,属于 materially different primary purpose,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个营销策略与执行支持技能,聚焦中国3C新品营销场景中的创意、渠道、预警、复盘等业务能力;而代码并未实现这些业务流程或策略生成能力。实际代码只是一个通用/半定制的评估工具:读取本地rubric配置,检查其结构合法性,并根据固定关键词对文本进行简单评分。虽然启发式关键词中包含“负面”“评论区”“数码”等与中国3C营销相关的术语,但这仅表明评分标准面向该领域,不等于实现了所宣称的营销策略技能包。主用途、能力边界和交互方式都明显不一致,因此属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个覆盖3C新品营销多环节的综合策略工具,重点在创意到执行、避雷、复盘等业务能力。实际代码却只是一个针对“route scorecard”样本的规则分类与数据校验脚本。它通过关键词判断文本属于“推荐/备选/弃用”,并验证样本文件结构,属于内部评测/质检工具性质。虽然“上线判断”之类场景可能与路线打分略有概念关联,但代码能力范围明显更窄,且核心目的是验证样本和分类片段,不足以支撑声明中的大部分营销功能,因此构成明显不匹配。

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/preprocess.py (reported line 167)May include surrounding context.

python
for rule in raw.get("categories", {}).get(category, []):
        if rule.get("name") and rule.get("keywords"):
            rules.append(rule)
    return rules

def detect_negative_signals(text, category, mode, rules=None):
    """根据离线规则识别负面早期信号。"""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L123 instructs the agent that '中国3C用户语言要具体、锋利、有证据', which effectively forces a China-specific language/style policy for outputs. The file does not state that the user can opt into another language or locale, so this is a natural-language locale policy constraint without explicit choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata and default prompt hard-code Chinese-language behavior and present the skill as the default path for relevant tasks without indicating any user choice. This can override user language expectations, reduce transparency, and increase the chance of miscommunication or unwanted behavior when the user did not ask for Chinese output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables implicit invocation without any trigger phrases or scope constraints, which can cause the assistant to route loosely related user requests into this marketing skill without clear user intent. Because the skill is specialized for Chinese 3C product marketing and can influence strategy, messaging, and risk decisions, accidental invocation can produce inappropriate, off-scope, or user-unexpected guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is entirely written as a Chinese output template and usage discipline, beginning with a Chinese title and prescribing fixed Chinese section names and status values. There is no indication that the user may choose another language or that the skill is limited to a China-specific or Chinese-only context, which makes this a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all operational guidance are written exclusively in Chinese, with no indication that another language is supported or that the Chinese-only requirement is optional. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and terminology exclusively in Chinese, and there is no indication that the user can choose another language or that the document is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON defines required visible markers entirely in Chinese, such as the frontstage and backstage section headers, which creates a language-specific constraint embedded in natural-language config. Because the file does not indicate user opt-in, alternatives, or a justified region-specific scope, it risks violating language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest-style JSON file contains user-facing natural-language content entirely in Chinese, including claims and required markers, but provides no indication that the skill is region-specific or that users can choose a language. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file encodes all decision labels and evaluation-required terms exclusively in Chinese, which can impose a fixed language requirement on downstream skill behavior or evaluation. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON file defines all user-facing values, including decision labels, expected verdicts, required terms, and sample inputs, exclusively in Chinese. Because the file provides no indication that the skill is region-specific or that users can opt into this locale, it appears to enforce a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-style JSON file contains required markers such as "[待验证]" and later "知识库暂无此数据", which impose Chinese-language responses as expected outputs. Because the file provides no opt-in, language choice, or explicit region-specific justification, it appears to enforce a specific language/locale in violation of the stated policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The required marker "知识库暂无此数据" mandates a Chinese-language response for the unsupported case. Under the policy, forcing a specific language is a violation unless the skill offers user choice or clearly documents a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language sample values are consistently written in Chinese across the entire dataset, including launch briefs, decisions, and action text, with no indication that the language is user-selectable or limited to a justified region-specific context. Because SQP-3 applies to all file types, this represents a locale/language policy concern in the sample content itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing natural-language instructions and examples exclusively in Chinese, and nowhere indicates that the skill is China-specific or that users may opt into another language. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rubric hard-codes Chinese-language output expectations such as '中国3C表达' and related fail conditions, which can force a specific locale even when the user did not request it. In a multi-platform skill, this can override user preference, reduce accessibility, and cause incorrect routing or unusable deliverables for non-Chinese-speaking operators or audiences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The JSON mixes Chinese route impact labels with English fact status labels, and the sample inputs are entirely Chinese. For a general-purpose skill artifact, this encodes a specific language/locale expectation without any natural-language indication that users can choose or opt into that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON sample set encodes all user inputs and expected response terms in Chinese, which effectively constrains the skill or evaluation behavior to a specific language. Under the stated policy, forcing a specific language without explicit user choice or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.