Back to skill

Security audit

消费维权指引

Security checks for vulnerabilities and agentic risk

Overview

This skill is a consumer-rights workflow guide that stores user-provided evidence locally for complaint preparation, with no signs of hidden execution or data exfiltration.

Before installing, understand that the skill may save complaint evidence such as receipts, payment screenshots, prescriptions, and chat logs in a local evidence folder. Use only evidence needed for the complaint, redact account numbers or medical details when possible, and remove the local evidence package after the matter is resolved.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to save user-uploaded evidence such as receipts, product packaging photos, payment records, prescriptions, and chat logs into a local workspace path. These materials can contain sensitive personal and financial data, but the skill does not clearly disclose local storage behavior, obtain consent, define retention/deletion limits, or recommend redaction/minimization. In a consumer-rights workflow, the data is especially sensitive because it may include medical, identity, and transaction evidence.

Static analysis

No suspicious patterns detected.