Back to skill

Security audit

外卖红包

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed food-delivery coupon link helper with no executable code, persistence, or credential access, though its broad trigger phrases could make it activate more often than users expect.

Installers should understand that ordinary food-related phrases may trigger this skill and return promotional coupon links from fore.vip. Use it when you want coupon links; if you prefer restaurant recommendations or neutral browsing, ask explicitly so the agent does not treat the request as coupon-seeking.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises broad natural-language triggers like coupon-seeking and food-browsing requests, which overlap with ordinary conversation and can cause unintended invocation. In an ecommerce context, accidental activation can redirect users to third-party affiliate links or influence purchase flow without clear user intent, creating consent and trust issues.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The listed utterances include vague everyday phrases like '看看有什么吃的' and '饿了', which are common conversational statements rather than explicit requests to invoke an affiliate-link skill. This increases the chance the agent triggers the skill when the user merely wants suggestions, causing unsolicited outbound requests and promotion of third-party links.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Defaulting ambiguous phrases such as '领券 / 看看有什么吃的 / 优惠 / 吃的 / 饿了' to this skill creates an overly permissive activation rule. Because the skill immediately performs HTTP requests and returns affiliate-style links, ambiguous matching can lead to unintended commerce actions and user manipulation through broad interception of normal food-related conversation.

Static analysis

No suspicious patterns detected.