Back to skill

Security audit

菜单结构与定价台

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese restaurant menu pricing guidance skill with no code, network access, credential use, persistence, or hidden authority.

Safe to install for menu pricing help. Users should still verify actual costs, losses, labor allocation, local competitor prices, legal claims, and final pricing decisions before using the output operationally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L66-L67 的触发示例“按上面的结果改成更简短的版本”“把这些整理成一张表”属于常见日常表达,本身不具备餐饮定价领域限定,容易与其他技能或普通对话请求重叠。虽然前文列出了一些较具体关键词,但这里没有明确说明这些宽泛表达仅在本技能已进入上下文后才适用,也缺少负面示例或排除条件。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

文件整体仅以中文描述技能名称、摘要、触发词和使用说明,未见任何允许用户选择输出语言或说明该技能仅面向特定中文地区用户的显式声明。根据规则,若技能隐含固定语言/locale 而未提供用户选择或合理限定,属于自然语言层面的语言政策风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.