Back to skill

Security audit

外贸询盘回复台

Security checks for vulnerabilities and agentic risk

Overview

This is a simple trade-inquiry email drafting skill with no code execution, persistence, credential access, or external data movement.

Installers should expect this skill to help draft trade inquiry replies from information they provide. Avoid entering unnecessary personal or confidential customer data, and verify prices, lead times, certifications, and payment terms before sending any generated email.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger keywords are broad, generic business phrases like '外贸邮件' and '客户问价' that can match ordinary user requests outside the intended bounded workflow. In agent-routing systems, overly broad triggers can cause this skill to activate unexpectedly, intercepting unrelated conversations and increasing the chance of inappropriate prompt injection, misrouting, or data exposure to the wrong skill context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language examples include generic editing requests such as '按上面的结果改成更简短的版本' and '把这些整理成一张表', which are not sufficiently anchored to the foreign-trade inquiry domain. If used by a dispatcher or matching heuristic, these examples can broaden the skill’s selection boundary and cause activation on general rewriting tasks, creating scope confusion and possible leakage of unrelated business content into this skill flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.