Back to skill

Security audit

Ecommerce Copy Humanizer KR

Security checks for vulnerabilities and agentic risk

Overview

This is a content-only Korean ecommerce copywriting skill with no code, network access, persistence, or hidden authority.

Install this if you specifically want Korean-market ecommerce copy rewriting. Users should expect Korean templates and style guidance, and should still independently verify legal or platform-compliance claims before publishing ads or product pages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description and body explicitly constrain the skill to Korean ecommerce rewriting and Korean-native style, but there is no indication that users may choose another language or opt into this locale restriction. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the constraint is clearly documented and justified as region-specific.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The checklist explicitly requires "한국어 자연스러움" and bans awkward translation style and unnecessary loanwords, which imposes a specific language/locale requirement. In this file there is no indication that Korean-only output is optional, user-selected, or justified as a region-specific skill.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The entire template is written in Korean, including the title and section labels, which implicitly requires outputs in a specific language. Under the policy, language constraints should either offer user opt-in/choice or be clearly documented as justified for a region-specific use case, neither of which appears here.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file is entirely framed as a Korean writing guide and provides prescriptive style instructions only for Korean-language ecommerce platforms. Because the content fixes a specific language/locale without any opt-in or explicit justification in the file, it matches the policy category for language or locale constraint violations.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This markdown file contains natural-language guidance exclusively in Korean, which can amount to a language/locale constraint without user opt-in. The policy for this audit flags content that forces a specific language unless the file explicitly offers a choice or documents a justified locale restriction.

Static analysis

No suspicious patterns detected.