Back to skill

Security audit

卖家之家(跨境电商)平台一体化服务助手(服务商、物流、服务产品、技能商城、货盘、资讯、问答、供需、私信、全球开店、活动)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent MJZJ platform API helper, but it gives agents authenticated access to private messages, public posting, and deletion actions without clear confirmation safeguards.

Review this skill before installing. It appears to be a legitimate MJZJ API reference skill, but only use it with an API key you are comfortable granting access to account data and actions. Agents using it should ask before sending private messages, publishing content, uploading files, refreshing posts, or deleting supply-demand items, and should show the target recipient, content, or item id first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly enables access to account-scoped conversations/messages and sending private messages, but it does not require explicit user confirmation, privacy notice, or clear distinction between read and send actions. In an agent setting, this creates a real risk of unauthorized disclosure of private data or unintended outbound communication using the user's authenticated API key.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents a destructive delete endpoint for supply/demand posts without any confirmation or safeguard language. In an autonomous or semi-autonomous agent flow, this can lead to accidental or induced deletion of user content through ambiguous prompts or prompt injection, causing integrity loss for account data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.