Back to skill

Security audit

Custom Order Support

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent customer-support aid with a small ETA script, but users should apply privacy and consent checks before SMS or third-party loyalty outreach.

Before installing, confirm the ETA calculator fits your store policy and require explicit consent and privacy review before using SMS, email marketing, or any third-party loyalty/review automation with customer order data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared description promises a comprehensive post-purchase support capability for long-lead custom products, including status inquiries, delays, modification requests, damage/quality complaints, and return eligibility. The supplied code only calculates estimated production and delivery milestones from an order date and parameters, plus a 24-hour modification deadline and rush adjustment. While timeline estimation is relevant to a subset of the declared use cases such as production timeline or 'order taking too long,' the actual code does not support the broader stated behaviors. There is no integration with orders, shipment systems, complaint handling, returns logic, or customer-support decisioning. Therefore the description materially overstates the skill's functionality relative to the code.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill directs operators to send Email/SMS updates and use a third-party service for post-delivery outreach without warning about privacy, consent, or data-sharing implications. In a support context, this can lead to personal data being used for additional communications or transferred to external vendors without proper notice, legal basis, or minimization controls.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill expands from customer support into loyalty, referral, and review automation through a third-party service, which broadens data use beyond the user's immediate support request. That scope creep can cause unauthorized secondary use of customer contact/order data and create compliance and consent issues, especially if operators assume the skill is limited to support handling.

Static analysis

No suspicious patterns detected.