Back to skill

Security audit

卖家之家(跨境电商)服务商搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly searches public provider listings, but it asks for an API key and includes authenticated private-message guidance that goes beyond plain search.

Review this skill before installing if you only want public search. It requests MJZJ_API_KEY despite saying search does not need authentication, and its documentation can lead an agent from lookup into authenticated private messaging through another skill. Only provide the API key and allow contact actions when you intend the agent to message selected providers on your behalf.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is advertised as a public service-provider search tool, but the documentation extends its workflow into authenticated private-message initiation via another skill. This broadens the effective capability scope from passive lookup to outbound contact, which can lead an agent to perform higher-risk actions than the user may expect from a search skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes message-sending guidance that is not required for the stated purpose of searching providers. This creates capability creep and increases the chance that an agent transitions from information retrieval to action-taking without strong user intent verification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes directly sending private messages to external parties without requiring an explicit warning or confirmation for an authenticated contact action. That can cause unauthorized or surprising outreach, especially when an agent chains the returned userSlug into a messaging API automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

1) 获取服务商分类(公开)

bash
curl -X GET "https://data.mjzj.com/api/spQuery/getClassifies" \
  -H "Content-Type: application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

1) 获取服务商分类(公开)

bash
curl -X GET "https://data.mjzj.com/api/spQuery/getClassifies" \
  -H "Content-Type: application/json"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The trigger and routing instructions are written entirely around Chinese phrases such as “卖家之家服务商”, “服务商查询”, and “查服务商”, and the description does not offer any language or locale choice. This can constitute a language/locale policy issue because the skill appears to hard-code Chinese-language invocation expectations rather than documenting an opt-in or region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.