Back to skill

Security audit

跨境电商注册地推荐

Security checks for vulnerabilities and agentic risk

Overview

This skill is an informational company-registration comparison guide with no executable code, persistence, credential access, or automatic filing behavior.

Installers should treat the output as planning guidance only. Confirm jurisdiction-specific requirements with a qualified lawyer, tax adviser, or registered agent before hiring providers, filing formation documents, applying for EIN/BOI, opening bank accounts, or relying on cost and tax estimates.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation examples are broad, natural-language business questions that can cause the skill to activate for generic commerce or legal/tax-adjacent queries without clear boundaries. In a skill that provides company-setup recommendations, overbroad triggering increases the chance of unsolicited or mis-scoped guidance in situations where jurisdiction-specific compliance or regulated advice should be handled more carefully.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad, common phrases such as “注册流程是什么”, “哪个国家注册最便宜”, and “美国公司怎么注册”, which can match many ordinary conversations outside the exact intended workflow. This increases the chance of accidental invocation, causing the agent to enter a compliance-oriented company-setup flow when the user may have meant a general informational query, leading to irrelevant guidance or unintended downstream actions.

Static analysis

No suspicious patterns detected.