Back to skill

Security audit

ecom-after-sales-cs

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only customer-service response skill with no code or persistence, but users should supply verified policy details before relying on its example remedies.

Install only if generated replies will be grounded in current brand policy and reviewed before sending. Treat the example refund, shipping, timing, and compensation values as placeholders, not default policy commitments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Unverified Commercial Policies and Financial Commitments in Response Examples

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-21, 23-32, 48-55, 59-65, 70-75
Vulnerability Type: Unverified policy generation and unauthorized commercial commitments
Risk Level: Medium

Evidence

The authoritative policy field is optional:

markdown
| 字段 | 类型 | 必填 | 说明 |
|------|------|------|------|
| scenario | enum[退换货申请,物流异常咨询,售后补偿协商] | 是 | 当前售后场景类型 |
| user_message | string | 是 | 用户原始咨询内容 |
| order_info | string | 否 | 订单号、商品、金额等上下文 |
| policy_hint | string | 否 | 本单适用的售后政策摘要 |

The response rules prohibit fabricated policies and commitments beyond authorization:

markdown
## 应答规范(response_rules)

1. **问候先行**:以品牌标准问候语开头,称呼用户为"您"
2. **共情表达**:先对用户遭遇表示理解/歉意,再做处理说明
3. **政策引用**:明确引用退换货/物流/补偿政策条款,禁止编造规则
4. **方案明确**:给出唯一或有限可选项,避免模糊措辞(如"可能""大概")
5. **操作指引**:分步骤说明用户需执行的操作,步骤编号清晰
6. **时效承诺**:注明处理/退款/补发预计时效
7. **服务收尾**:以"感谢您的理解与支持"类话术结束,留联系方式
8. **禁止承诺超权限内容**:不得承诺超出品牌授权的补偿方案

However, the examples contain concrete, unverified return conditions, deadlines, shipping obligations, refund rights, and compensation amounts:

markdown
**用户**:我收到的衣服尺码不对,想换货,订单号DD20260512001

**客服**:您好,非常抱歉给您带来不便!理解您收到尺码不符商品的心情。根据我们的退换货政策,支持签收后7天内无理由换货。为您办理换货流程如下:
1. 请在"我的订单"中找到订单DD20260512001,点击"申请换货"
2. 选择换货原因"尺码不符",填写正确尺码
3. 提交后系统将在1个工作日内审核,审核通过后寄回地址将以短信发送给您
4. 我们收到退回商品并验收后,将在2个工作日内为您寄出正确尺码的商品
换货期间运费由我方承担,请您放心。感谢您的理解与支持!如有其他疑问,可随时联系在线客服。
markdown
**用户**:我的快递已经5天没更新了,是不是丢了?订单DD20260508003

**客服**:您好,非常理解您的担忧!物流长时间未更新确实让人着急。我们马上为您核查订单DD20260508003的物流状态。处理方案如下:
1. 我方将立即联系物流公司进行件态追踪,预计1-2个工作日内反馈结果
2. 若确认包裹丢失,我们将为您免费补发同款商品或办理全额退款
3. 若包裹仍在运输途中,我们将提供加急配送方案
请您稍候,我们的专员会在24小时内通过短信或电话与您联系告知进度。感谢您的耐心等待!如需进一步帮助,可随时联系在线客服。
markdown
**用户**:收到的商品有划痕,虽然不影响使用,但心里不舒服,你们得给个说法吧?

**客服**:您好,非常抱歉商品出现划痕影响了您的体验!您的感受我们完全理解。根据售后补偿政策,针对商品外观瑕疵,我们提供以下补偿方案供您选择:
1. 方案A:保留商品,补偿20元无门槛优惠券(3个工作日内到账)
2. 方案B:保留商品,补偿10元现金退款至原支付账户(3-5个工作日到账)
3. 方案C:办理退货退款,运费由我方承担
请您选择倾向的方案,我们将尽快
...[truncated 2431 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make policy_hint mandatory whenever a response includes policy terms, deadlines, refunds, shipping liability, replacement rights, coupons, or monetary compensation.
  2. Define a strict fallback when authoritative policy is unavailable. The response should acknowledge the request, state that the applicable terms require verification, and escalate the case without quoting specific benefits or deadlines.
  3. Replace concrete values in few-shot examples with clearly marked variables sourced from validated policy data, such as RETURN_WINDOW_DAYS, APPROVED_REFUND_OPTION, and AUTHORIZED_COMPENSATION_AMOUNT.
  4. Add an explicit rule that examples are formatting demonstrations only and must never be treated as policy sources.
  5. Require structured authorization metadata for financial commitments, including allowed remedy types, maximum values, eligibility conditions, approver identity, and policy version.
  6. Validate generated responses before delivery. Reject output containing financial amounts, processing deadlines, refund promises, replacement promises, or shipping obligations that are not present in the authoritative policy input.
  7. Route unsupported or exceptional compensation requests to human approval rather than generating a definitive commitment.
  8. Add tests covering missing, incomplete, conflicting, and expired policy information to verify that the Skill refuses to invent terms.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.