Back to skill

Security audit

Reverse Compliance

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed compliance-planning skill that uses user-provided business details and OpenAI for text generation, with no evidence of hidden persistence, destructive actions, or credential theft.

Install only if you are comfortable sending the product, market, platform, and compliance facts you provide to OpenAI for generation. Treat outputs as planning aids, not legal advice, and have qualified counsel verify jurisdiction-specific requirements before relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The description presents a broad strategic skill for cross-border compliance planning and competitive positioning, especially around GDPR, EU AI Act, GPSR, REACH, and trust/compliance frameworks. The code, however, only performs a relatively narrow operational audit of data privacy compliance across four dimensions using status inputs such as compliant/partial/non_compliant. It generates scores, issues, priority matrices, and roadmaps for remediation. While there is partial overlap with GDPR and cross-border compliance, the primary behavior is an audit/reporting utility for privacy/data-transfer compliance, not a strategic market-entry or compliance-architecture planning tool. Several declared triggers and named regimes are unsupported by the code, making the description materially broader and partly inaccurate.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly states that the skill uses a cloud-based OpenAI API and real-time regulation syncing, but it does not warn users that prompts, business plans, market-entry strategies, or compliance-sensitive data may be transmitted to third-party services. In a compliance-focused skill, users are especially likely to input confidential legal, product, and cross-border operational information, so the omission can lead to unintended disclosure and privacy/compliance risk.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation description is vague and expansive, which increases the chance of inappropriate activation across adjacent business, legal, and strategy discussions. Because this skill encourages users to provide company/product/market information and promises comprehensive outputs, ambiguous activation raises the risk of unnecessary disclosure and misplaced trust in generated compliance content.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is broad enough that the skill may activate in loosely related conversations, causing an LLM to provide confident compliance guidance when the user did not intend to invoke this specialized workflow. In a compliance context, accidental invocation can misroute user requests, elicit unnecessary business-sensitive data, and produce overbroad regulatory advice that users may mistakenly rely on.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill metadata and triggers are predominantly Chinese-focused, which can bias routing and response behavior toward Chinese-language interaction without explicit user preference. This is mainly a safety and usability issue: users may receive responses in an unexpected language or have the wrong skill selected, reducing clarity in a domain where precise legal/compliance communication matters.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger set includes generic business/compliance phrases that can match ordinary user discussions and cause this skill to activate outside a clearly intended scope. In a compliance strategy skill, over-broad routing is risky because it can inject specialized or persuasive compliance-planning behavior into unrelated conversations, increasing the chance of misleading advice or unintended data handling.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
该处使用“必须提供德语版SDS”的绝对化表述,属于自然语言层面的语言/locale 强制要求。虽然文档面向德国市场,但这里未明确说明这是因法定义务而仅限德国市场场景适用,缺少对语言约束的明确政策性限定,容易形成未经用户选择的固定语言要求。

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
“GPSR标签要素(德语)”以强制性形式指定单一语言,属于自然语言中的 locale 强约束。尽管德国市场通常需要德语信息,但文本本身没有同步说明这是德国市场法规限定下的要求,也未给出多语言或按目标市场切换的选项。

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
“标签规范(德语强制项)”是直接的单一语言强制表述,符合需要审查的语言/locale 政策问题。虽然上下文与德国市场有关,但该处未同时强调这是市场法规适配结果,而非通用技能输出或通用产品文档的默认语言策略。

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The article tells users to configure an OpenAI API key and submit product, market, and compliance data to an external AI service, but it provides no guidance on secure secret handling, least-privilege scoping, storage practices, or data privacy implications. In a compliance-focused skill, this is especially risky because users may upload sensitive business, regulatory, supplier, or market-entry information under the assumption that a 'compliance' tool is inherently trustworthy.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This code file contains user-facing documentation, CLI help text, and report content primarily in Chinese, and it does not offer any language selection or fallback. That creates a language/locale policy concern because users are implicitly forced into a single language experience without explicit opt-in or justification.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
Most user-facing instructional content, examples, triggers, and operational descriptions are presented in Chinese, and the skill does not state that users may choose another language. For a globally scoped compliance tool, this can be a language/locale policy concern if the user is not given an explicit opt-in or alternative.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
该检查项把德语说明书设为默认必备,属于自然语言中固定 locale 的要求。虽然对德国站点有现实依据,但条文没有说明这是针对德国消费者市场的法定要求,缺少范围限定和可迁移性说明。

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file presents all guidance and templates exclusively in Chinese, and it does not indicate that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Static analysis

No suspicious patterns detected.