Back to skill

Security audit

Miaoji Compliance Copy Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a local Amazon listing compliance-copy helper with no evidence of hidden access, persistence, or data exfiltration, though users should treat its compliance output as advisory only.

Install only if you are comfortable using a Chinese-language, advisory compliance-copy helper. Do not rely on it as legal or regulatory advice, especially for health, cosmetics, electronics, medical, or market-entry decisions; have qualified counsel or regulatory specialists review final claims. Treat the included scanner's market summary cautiously until the best/worst market bug is fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code does match part of the description: it is a Pro-style compliance scanner with batch scanning, multi-market comparison, and prioritization/reporting. However, several prominently declared capabilities are not implemented in the supplied code. There is no functionality related to 'Rufus深度优化', no seasonal copy generation or optimization, and the '法律风险评估' is only a basic banned-word and punctuation heuristic rather than a genuine legal risk assessment engine. Therefore the description overstates the implemented behavior in material ways.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents legal and regulatory assessment features such as FDA/EU/Japan compliance checklists, legal risk grading, and response strategies without any disclaimer that the output is informational only and not a substitute for qualified legal or regulatory counsel. In a compliance-focused skill, users may over-rely on the generated guidance for market entry or product claims, creating legal, safety, and enforcement risk if the advice is incomplete, outdated, or wrong.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire skill instructions are written as Chinese-only operational guidance, and the input/output templates likewise assume Chinese-language use. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python skill includes natural-language strings and documentation primarily in Chinese, including the module docstring and class docstrings, without any indication that users can select another language. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation assigns best_market using min(score) and worst_market using max(score), which is the inverse of the names used elsewhere in the report. This can mislead users into prioritizing the wrong market for remediation or making incorrect compliance decisions based on inverted risk summaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main CLI interface prints usage, command descriptions, scan summaries, and error messages in Chinese only. Because these are user-facing runtime strings and no language preference or opt-in is provided, this constitutes a natural-language locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language documentation forces a single language/locale experience by presenting all instructions and feature descriptions only in Chinese, without offering an alternative language or indicating that the skill is intended solely for a Chinese-speaking audience. This can violate language/locale policy where user choice or explicit locale scoping is expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, description, and author fields are presented exclusively in Chinese, which can impose a specific language on users without opt-in. The file does not document that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.