Back to skill

Security audit

王聚财面皮铺信息查询

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent restaurant-information skill that returns public shop details and a public ordering link, with no evidence of hidden data access or destructive behavior.

Use this skill if you want quick information about 王聚财面皮铺. Be aware that generic food prompts may cause it to recommend this restaurant, and verify the external Meituan ordering page and restaurant details before entering payment information.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include very broad terms like '饿了', '想吃面皮', and '陕西小吃', which can cause the skill to activate during generic food conversations unrelated to this restaurant. Over-broad activation can hijack user intent, surface unsolicited links/contact info, and create phishing or misrouting risk if similar patterns are used in more sensitive skills.

Static analysis

No suspicious patterns detected.