Back to skill

Security audit

Global E-Invoice partner selection

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent e-invoicing partner-selection skill that reads its own reference files, uses web research, and generates a report, with no evidence of hidden execution, persistence, or data exfiltration.

Before installing, confirm that you want a Chinese-first workflow for regulatory partner research. Treat its market reference data as starting material only: the skill itself correctly requires current official-source verification and legal confirmation before production decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents core descriptive content in Chinese at L003 and English at L005, but nowhere states a user language preference, fallback rule, or opt-in mechanism. This can violate a language/locale policy when a skill imposes or assumes multilingual output conventions without giving the user a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-requires professional Simplified Chinese output, which can override a user's language preference and cause unsafe misunderstandings if the user cannot accurately review the recommendations. In a partner-selection and compliance workflow, language mismatch can distort commercial, legal, or operational decisions, though it does not directly enable code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L038 写明“越南语强制:商品/服务名称必须含越南语描述”。该表述是自然语言层面的强制语言要求,但未说明这是特定国家合规要求下仅适用于越南发票字段,也未提供用户选择或明确限定,符合语言/locale policy violation 的检查项。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/country_regulatory_reference.md (reported line 81)May include surrounding context.

md
| **合规模式** | Post-Audit(事后审计)—— 无实时 CTC 要求,发票不经税局实时验证 |
| **通道类型** | Peppol Access Point(AP)—— 需持 IMDA 认证的 InvoiceNow AP 资质 |
| **我方目标资质** | IMDA 认证 InvoiceNow AP(当前约 35 家,2026-04 数据) |
| **官方名录 URL** | https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework(IMDA 官网);AP 完整名录:irsplistforwebsite.pdf(已在项目知识库) |
| **接入路径** | 通过 Storecove 接入 Peppol InvoiceNow(Phase 2 路径,P0 blocker:Storecove C5 API 就绪确认) |
| **已知目标合作方** | **SESAMi**(第一梯队:InvoiceNow 奖历年第一,Best Performance AP);**DataPost**(第一梯队:Direct Connection 奖,成本效率高);**Storecove**(接入层,非 AP,提供 C5 API) |
| **发票格式** | UBL 2.1(Peppol BIS Billing 3.0) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that other languages are supported or that Chinese is a required locale for a specific regional compliance workflow. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The acceptance criterion requires error reasons to be converted into readable Chinese descriptions, which imposes a specific language/locale requirement. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific compliance constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.