Back to skill

Security audit

Ecommerce Copy Humanizer JP

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only Japanese e-commerce copywriting skill with no execution or persistence behavior, but users should independently verify promotional and regulated product claims before publishing.

Use this skill for Japanese-market e-commerce draft copy, but review every factual, numeric, discount, certification, testimonial, health, cosmetic, or performance claim against current evidence and platform rules before publishing. It should not be used as a legal, medical, financial, or advertising compliance review tool.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/ai-patterns-jp.md:48
Finding

Rewrite Example Introduces Unsupported Skincare Efficacy Claims

Content
View full analysis

Vulnerability Details

File Location: references/ai-patterns-jp.md, lines 48-54
Vulnerability Type: Unsafe generation guidance that introduces unsupported commercial and health-related claims
Risk Level: Medium

Vulnerable Content

markdown
### Example 1 — Skincare product page

Before: This product, made with innovative technology and premium ingredients, provides the best care for your precious skin.

After: This one cream solved my dry, tight-feeling skin. Formulated with a five-part hyaluronic acid complex—you will definitely feel the difference 20 minutes after application.

The snippet above is an English translation of the Japanese source content. The translated assertions correspond to the original claims that one cream “solved” dry skin and that users will “definitely” perceive a difference after 20 minutes.

Technical Analysis

The recommended rewrite introduces specific efficacy assertions that are absent from the input. In particular, it converts generic promotional language into a claim that the product solved a skin condition and a definite, time-bound promise that every user will perceive a result after 20 minutes.

This conflicts with the Skill's own controls against unsupported promises, absolute statements, and medical or quasi-medical efficacy claims. Because this content is presented as an approved “After” example, an Agent may imitate it even though later checklists advise against absolute claims. Explicit examples can exert stronger behavioral influence than abstract safety rules.

The issue does not enable operating-system access, code execution, or privilege escalation. It is classified under insecure Skill practices because the bundled guidance can systematically produce deceptive or noncompliant output.

Attack Path

  1. A user submits vague or exaggerated skincare copy without test results or substantiating evidence.
  2. The Agent loads this file as the prescribed rewri ...[truncated 1041 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unsafe rewrite with language that does not create new facts or guarantee outcomes.
  2. Require every quantitative, efficacy, timing, ingredient, certification, and test claim to be present in user-provided source material and supported by verifiable evidence.
  3. Use explicit placeholders such as [verified test result] rather than fabricated figures or outcomes.
  4. Add a mandatory rule stating: “Never add product facts, customer experiences, test results, certifications, or efficacy claims that were not supplied and substantiated by the user.”
  5. Require the Agent to flag unsupported claims for verification instead of rewriting them as facts.
  6. Add category-specific safeguards for cosmetics, healthcare, supplements, medical devices, and other regulated products.
  7. Make the compliance review authoritative over all style examples and require regeneration when any absolute or unsupported statement is detected.
  8. Use a safer example such as: “Formulated with a five-part hyaluronic acid complex to support moisture care for skin prone to dryness,” but only if the formulation claim is verified.

T09 · Insecure Skill Coding Practices

Warning
Location
references/platform-guide-jp.md:11
Finding

Platform Examples Encourage Unverified Certifications, Metrics, Discounts, and Performance Claims

Content
View full analysis

Vulnerability Details

File Location: references/platform-guide-jp.md, lines 11-14 and 28-34
Vulnerability Type: Unsafe promotional examples without mandatory evidence validation
Risk Level: Medium

Vulnerable Content

markdown
Examples:
✅ Machine washable — tested for 200 wash cycles
✅ Skin irritation tested (dermatologist certified)
✅ One package provides a 30-day supply

Effective hooks:
- Empathy hook: “I was struggling with ○○.”
- Before-and-after hook: “There really is a difference between before and after use.”
- Question hook: “Are you still using ○○?”
- Numeric hook: “There is a reason 40,000 people added this product to their favorites.”

Style: Conversational language, short sentences, and a strong call to action: “Tap the link now for ○% off.”

The snippet above is an English translation of the Japanese source content. It preserves the factual meaning of the original examples.

Technical Analysis

The platform guide presents performance testing, dermatologist certification, product duration, popularity figures, before-and-after outcomes, and discount percentages as recommended copy patterns. It does not make their use conditional on evidence supplied by the user.

These statements are externally verifiable factual representations rather than stylistic wording. If an Agent treats the examples as reusable templates, it may invent a wash-test result, certification, customer-engagement figure, product duration, discount, or efficacy outcome. Placeholder symbols reduce the risk for some fields but do not establish a mandatory verification boundary.

The file's guidance conflicts with the separate risk checklist, which requires evidence for rankings, discounts, reviews, and similar claims. This inconsistency makes enforcement unreliable because the platform examples positively reinforce the same claim types that the compliance rules restrict.

Attack Path

  1. A user requests c ...[truncated 1234 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefix every factual example with an explicit condition such as “Use only when supported by current, documented evidence supplied by the user.”
  2. Replace concrete sample figures and certifications with clearly marked placeholders:
    • [verified wash-test count]
    • [exact certification and issuing organization]
    • [verified favorite count and measurement date]
    • [active discount and validity period]
  3. Prohibit the Agent from inferring or inventing certifications, test outcomes, inventory levels, popularity metrics, discounts, customer experiences, and before-and-after results.
  4. Require provenance metadata for factual promotional claims, including source, measurement period, testing method, applicable product model, and expiration date where relevant.
  5. When evidence is unavailable, instruct the Agent to omit the claim and list it under a “Verification required” section.
  6. Add a final consistency rule stating that compliance requirements override conversion and platform-style recommendations.
  7. Expand the final checklist to verify performance tests, professional endorsements, popularity metrics, discounts, product duration, and testimonial-style first-person statements.
  8. Prevent automatic publication of output containing unresolved placeholders or unverified claims.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description and core instructions specify rewriting specifically for Japanese ecommerce platforms and natural Japanese copy, which imposes a fixed language/locale behavior. The file does not indicate that users may choose another language or explicitly opt into this locale restriction, so it matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The checklist explicitly requires Japanese naturalness and specifically references how Japanese EC sellers or operations teams would write. This is a natural-language locale constraint, but the file does not indicate that the skill is optional, user-selected for Japanese output, or restricted to a Japan-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is explicitly scoped to Japanese copy patterns and presents the guidance only in Japanese, which constitutes a locale-specific constraint. The file does not offer a language choice or explain why Japanese-only guidance is required for a region-specific or compliance-driven purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and instructions specify a Japanese-specific output template ("JP" and Japanese-language content) and require that all rewritten results follow this format. This imposes a language/locale constraint without any visible user opt-in or alternative language option, which matches the policy-violation category for forced language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title 'ECプラットフォーム別文体ガイド — 日本' indicates the skill content is tailored to Japanese output. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the constraint is clearly justified as region-specific; this file does not state such a justification or present language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title states this is a Japan-specific checklist and the entire content is presented only in Japanese. Under the policy rule, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.