Security audit
卖家之家(跨境电商)资讯搜索与发布
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed MJZJ article search and publishing helper that can use an API key to manage and publish account content.
Install this only if you trust MJZJ and want an agent to help manage or publish articles there. Keep MJZJ_API_KEY private, review author identity, tags, article HTML, images, and publish time before publishing, and avoid importing HTML or media from untrusted sources.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
