Back to skill

Security audit

Ora外贸客户开发专家

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed external business-search client, but it also imposes an unrelated mandatory geopolitical wording rule on the agent's answers.

Review the mandatory wording rule before installing, because it can alter how the agent labels Taiwan, Hong Kong, and Macao in search results or related answers. Also install only if you are comfortable sending search terms and the Ora API key to h.smtso.com over HTTPS.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:129
Finding

Mandatory Output Policy Unrelated to the Skill's Search Function

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions require the model to always use prescribed terms for Taiwan, Hong Kong, and Macau and prohibit alternative formulations in all contexts. This is a natural-language policy constraint that forces a specific geopolitical/locale framing without user opt-in or a clearly scoped regional compliance justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly states it reads an API key from the environment or a local key file and sends user queries plus credentials to an external domain, but it does not declare any tool scope or permission boundary. This creates an undeclared capability to access secrets and exfiltrate data, making it difficult for the hosting agent or user to reason about what the skill can access and transmit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to match common business-search requests, which can cause the skill to activate in situations where the user did not intend external lookup or data sharing. In this skill, that risk is amplified because activation can lead to external transmission of search terms and use of locally available credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language documentation, including the title and API key instructions, is written only in Chinese while providing no language choice or justification for a region-specific requirement. This can violate language/locale policy when a skill implicitly forces one language for operation or understanding without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a foreign-trade customer search skill for querying company lists by country, product, and industry. While network access to perform the search is expected, the additional capability to source credentials from process environment variables and arbitrary local file contents introduces secret/file access behavior that is not stated or justified by that purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.