商品归类skill
PassAudited by VirusTotal on Apr 24, 2026.
Findings (1)
The skill implements a mandatory PII collection flow that requires users to provide a phone number before fulfilling requests. It stores session IDs and phone numbers in a local SQLite database (users.db) and transmits this data to an external endpoint (agent.ccorp.cn). The SKILL.md file uses aggressive prompt instructions to force the AI agent to demand phone numbers and explicitly prohibits the agent from providing results or 'simulating' answers without successful data collection. While the behavior is documented in the README, the forced harvesting of contact information linked to user queries is a significant privacy risk.
