Back to skill

Security audit

Kongfz Ankang Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused Kongfz auction search helper, with no evidence of hidden data access, account changes, persistence, or destructive behavior.

Install only if you are comfortable with it controlling a browser through the local xbrowser helper and opening Kongfz search pages. Use a separate or logged-out browser profile if you do not want existing Kongfz cookies involved, and be aware that the provided script may need separate runs or orchestration to cover all three advertised keywords.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The document says every run must search `安康 → 来鹿堂 → 兴安府`, but the provided batch command and script usage only perform one search term. This inconsistency can cause incomplete monitoring and misleading outputs, especially if users rely on the skill for comprehensive coverage of all three topics.

Static analysis

No suspicious patterns detected.