Back to skill

Security audit

电商详情页文案生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Chinese e-commerce copywriting helper, but it includes templates for generating credible-looking customer reviews, which can enable deceptive marketplace behavior.

Review this skill carefully before installing. It is technically low risk to your device, but only use it for truthful product-page copy, authentic review summaries, or review-request drafts; do not use it to invent customer reviews, fake usage experiences, unsupported certifications, sales numbers, or artificial scarcity claims.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown explicitly specifies 'Output Language' followed by '中文输出', which imposes a single language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is documented as justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, framing the skill as a Chinese copywriting generator without any indication that users may select another language or locale. Under the policy, a skill that imposes a specific language without user opt-in can violate language/locale requirements.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

These lines describe a multi-step sequence that first establishes trust and then culminates in a conversion push, which matches a gradual persuasive narrative pattern. While framed for e-commerce copywriting, the instruction sequence itself is a clear example of incremental influence through staged trust-building and urgency.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

The template lays out a sequential narrative: emotional pain-point framing, value presentation, rational persuasion, immersion, comparison, reassurance, and finally a closing commitment step. Individually benign, the combined progression is a classic gradual-influence pattern that aligns with narrative deception or incremental steering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly provides templates for generating 'seed reviews' and comparative praise, which can enable fabrication of testimonials rather than legitimate product-page copy. In an e-commerce skill, this crosses from persuasion into deceptive content generation and can facilitate review manipulation, consumer fraud, and marketplace policy violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.