Back to skill

Security audit

03 Logistics Alert

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only logistics skill is purpose-aligned and has no hidden execution, exfiltration, or persistence, but users should avoid sharing unnecessary personal order data.

Install only if you are comfortable pasting logistics order details into the agent. For real orders, provide the minimum needed fields and redact personal identifiers that are not necessary for anomaly classification or compensation estimation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly solicits order and tracking data but provides no privacy notice, minimization guidance, or warning against including unnecessary personal information. In a logistics/internal-control context, users may paste names, phone numbers, addresses, and order identifiers, creating avoidable exposure of sensitive operational and personal data through the skill pipeline.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The batch-upload workflow encourages submission of multiple orders without explaining processing scope, sensitive-field handling, or the consequences of bulk disclosure. Because batch datasets can contain large volumes of customer and supplier information, missing warnings and controls materially increase the risk of mass privacy leakage and oversharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该段把“描述某个包裹的具体情况”“询问某类异常的标准或赔偿规则”等宽泛表述直接作为进入预警流程的条件,但没有限定必须包含哪些字段、业务上下文或排除哪些普通咨询场景。这类触发描述容易与日常物流问答或一般规则咨询重叠,增加非目标场景下被调用的风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.