Back to skill

Security audit

E-Commerce After-Sales CS

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only e-commerce customer service drafting skill with one wording inconsistency but no code, hidden access, persistence, or external data handling.

Suitable to install as a drafting aid. Before using generated replies with customers, verify order facts, refund limits, compensation authority, and revise the example phrase using “一定” so agents do not copy an over-promising response.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill’s own rules forbid absolute guarantee language, but the compensation example says “我们一定尽力让您满意,” creating an internal contradiction that can train or nudge agents to use prohibited wording. In a customer-service prompt skill, inconsistent examples are high-leverage because examples are often copied verbatim, which can lead to policy-noncompliant promises and customer disputes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.