Back to skill

Security audit

跳舞兰订花平台,全国2-24小时送花到家

Security checks across malware telemetry and agentic risk

Overview

This flower-ordering skill matches its stated purpose, but it creates real orders and sends recipient personal details to an external service without a clear privacy or final-consent step.

Install only if you are comfortable using this specific Tiaowulan ordering flow. Before submitting an order, confirm the product, price, recipient name, phone number, full address, card text, delivery time, and that this data will be sent to the external order API; do not enter recipient details unless you have permission to use them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad consumer terms like '买花', '花店', and '选一束花', which can match ordinary conversation and cause the skill to activate unexpectedly. Because this skill proceeds into product recommendation and order-taking flows, accidental invocation can steer users into a commerce and data-collection interaction they did not explicitly intend.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill instructs collection of sensitive personal data including recipient name, mobile number, detailed address, card message, and delivery time, then transmits it to a third-party endpoint without any visible privacy notice, consent language, retention policy, or data-handling disclosure. In the context of gift delivery, these fields are sufficient to expose personal identity, location, contact details, and behavioral information, increasing privacy and misuse risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.