Back to skill

Security audit

全球电子发票合作伙伴甄选

Security checks for vulnerabilities and agentic risk

Overview

This is a focused e-invoicing partner-selection reporting skill, and I found no hidden execution, persistence, credential handling, or destructive behavior.

Install this only if you want an opinionated Simplified Chinese workflow for e-invoicing partner evaluation. It will need web access for current official registries and will create a report file, but the reviewed artifact does not request credentials, broad local access, automatic execution, or persistent agent control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '使用专业的简体中文' forces a specific language for all outputs. Under the policy, locale or language restrictions should either provide user choice or be clearly justified as region-specific; this file does not do either.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document title and all operational guidance are written exclusively in Chinese, and there is no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/country_regulatory_reference.md (reported line 81)May include surrounding context.

md
| **合规模式** | Post-Audit(事后审计)—— 无实时 CTC 要求,发票不经税局实时验证 |
| **通道类型** | Peppol Access Point(AP)—— 需持 IMDA 认证的 InvoiceNow AP 资质 |
| **我方目标资质** | IMDA 认证 InvoiceNow AP(当前约 35 家,2026-04 数据) |
| **官方名录 URL** | https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework(IMDA 官网);AP 完整名录:irsplistforwebsite.pdf(已在项目知识库) |
| **接入路径** | 通过 Storecove 接入 Peppol InvoiceNow(Phase 2 路径,P0 blocker:Storecove C5 API 就绪确认) |
| **已知目标合作方** | **SESAMi**(第一梯队:InvoiceNow 奖历年第一,Best Performance AP);**DataPost**(第一梯队:Direct Connection 奖,成本效率高);**Storecove**(接入层,非 AP,提供 C5 API) |
| **发票格式** | UBL 2.1(Peppol BIS Billing 3.0) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all operational instructions and acceptance criteria only in Chinese, with no opt-in, alternative language, or stated region-specific language requirement, which can force a specific language on users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest describes this skill as being used to find, filter, and evaluate local e-invoicing partners and to provide traceable reasoning plus recommendations. The file goes beyond pure partner-selection analysis by requiring generation of a .docx file and invoking the docx skill, which is a document-production behavior not stated in the manifest description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The stated purpose is partner selection, filtering, evaluation, POC design, and negotiation framing. The mandated '三宗罪' section and explicit instruction to state that a company '不用再讨论' pushes the skill into hard negative adjudication/blacklisting behavior, which is stronger than ordinary partner evaluation and not clearly justified in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is entirely written in Chinese and provides no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.