Back to skill

Security audit

商品比价技能

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese ecommerce price comparison helper, but its risk recommendations should be treated cautiously because of an implementation bug.

Install only if you are comfortable using it for Chinese-market ecommerce comparisons and manually verifying important purchase decisions. Treat the generated risk level as advisory, especially until the nested risk_level handling is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/price_analyzer.py:372
Finding

Risk Ratings Are Misread and Can Be Associated with the Wrong Platform

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向电商比价场景的分析与决策技能,应当包含跨平台价格汇总、价格/平台信息分析、风险识别,以及基于分析结果给出购买建议。实际代码并未实现这些核心能力。它只从命令行接收一段 JSON,验证字段如 product_name、price_list、platform_info、platforms、region、user_priority 的存在性、类型和基本取值范围,然后返回校验结果。虽然字段名与电商比价场景相关,但这只是输入校验这一支持性功能,不能代表所声明的主要用途。因此,代码行为与描述存在实质性不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

文件标题及全文内容均以中文编写,用作技能规则文档时会默认强制该语言,但文档中没有说明这是面向中文用户的限定场景,也没有提供语言选择或用户选择机制。根据规则,未提供 opt-in 的固定语言约束属于自然语言策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains its top-level docstring, CLI usage text, and error messages entirely in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are offered a choice or the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code comment and docstrings state that steps 4 and 5 generate user-decision and risk-explanation outputs from prior risk scoring, but the objects appended at L384-L388 store risk data under "risk_assessment" while L285 and L343 read "risk_level" directly from the outer dict. This means the generated recommendations and explanations will not actually reflect the computed risk results, diverging from the documented analysis intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

文件标题及全文以中文规范形式呈现,并在 L011 使用“所有输入数据必须符合此格式”的强制性表述,但没有说明这是面向特定中文区域用户,或提供其他语言版本/用户选择。根据规则,强制特定语言而无用户选择或明确业务合理性,属于自然语言层面的语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The guidance states that if the user does not specify a region, the agent should default to Mainland China. This imposes a locale/region assumption rather than offering a user choice, which matches the policy category for language or locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains natural-language descriptions and CLI usage/output strings entirely in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, alternative locale, or explicit justification that the skill is intended only for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.