Back to skill

Security audit

国产产品核查

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent product-verification purpose, but it automatically saves screenshots, product images, and purchase receipts locally without clear opt-in, redaction, or deletion controls.

Review before installing. Use it only if you are comfortable with the agent saving product photos, screenshots, and purchase evidence locally. Avoid providing unredacted receipts unless needed for a complaint, and delete the generated evidence package when finished.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill instructs collecting and retaining a purchaser's receipt in an evidence package, which can contain personal data, transaction identifiers, store details, and payment metadata unrelated to routine product qualification verification. This creates unnecessary data collection and retention risk, especially if the workspace is later accessed by other tools, users, or synced systems.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The automatic creation of a local 'evidence package' stores screenshots, product images, and receipts on disk beyond what is necessary for a simple authenticity check. This broad retention increases the chance of sensitive information exposure and creates a persistence risk if local files are later reused, leaked, or inspected without the user's awareness.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are broad enough to match common requests like 'check this product' or 'see if this is OK,' which can cause the skill to activate in contexts where the user did not intend a regulatory-style investigation. Unintended invocation is risky here because the skill later directs screenshot capture and evidence retention steps.

Vague Triggers

High
Confidence
95% confidence
Finding
Automatically triggering on any product image is overly ambiguous and can invoke the skill without clear user consent or relevance. In this skill's context, unintended activation is more dangerous because it can lead to extracting packaging details, querying third-party sites, and saving screenshots or evidence files without an explicit user request.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The instruction to 'immediately' save browser screenshots of query result pages introduces silent persistence of potentially sensitive information, including product, seller, and account-linked browsing context. Because the skill does not clearly warn the user beforehand, it undermines informed consent and increases privacy risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill specifies automatic generation of a local evidence package containing images, receipts, and screenshots, but does not clearly disclose this storage behavior up front or obtain explicit consent. This is a direct privacy and data-governance issue because sensitive user-provided materials may be retained locally without necessity or awareness.

Ssd 3

Medium
Confidence
91% confidence
Finding
Preserving user-provided purchase evidence and screenshots in a structured local evidence package creates a natural-language-driven data retention channel that may accumulate sensitive documents over time. Even if intended for consumer protection, this persistence broadens exposure to unauthorized access, secondary use, and accidental disclosure.

Static analysis

No suspicious patterns detected.