Back to skill

Security audit

外贸文案生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Markdown copywriting skill for foreign-trade outreach, with no executable code or hidden high-impact behavior found.

Before using it, confirm the target market, preferred language, and any legal or certification claims yourself; the skill provides marketing drafts and localization heuristics, not verified compliance advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes natural-language instructions such as '阿拉伯语为主', '英语', and '西班牙语/葡萄牙语' as expected language requirements for outreach by market. Because the guidance presents fixed language rules rather than offering a user-selected language/locale option, it can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file states '目标语言输出(默认英语)', which imposes English as the default output language unless the user specifies otherwise. Under the policy, forcing a specific language without user opt-in can be a locale/language policy concern, even though the skill also supports multiple languages elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entry for France lists '英语过多' as a behavioral taboo, which effectively discourages use of English in a way that can force locale behavior. This is a natural-language policy concern because it prescribes language use without presenting it as an optional, user-directed preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.