Back to skill

Security audit

Skill Guangjiao

Security checks for vulnerabilities and agentic risk

Overview

This Canton Fair lead-generation skill is coherent, but it needs review because it can use an API key, export contact data, and send email or WhatsApp outreach with unclear approval controls.

Install only if you trust the publisher and Yunlv MatchGPT API with your Canton Fair lead queries and are prepared to handle contact data responsibly. Require explicit review of recipients, channels, message text, language, storage location, and follow-up timing before any export or email/WhatsApp action.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains broad, common phrases such as '广交会', '参展商', and '展会数据' that can easily appear in ordinary discussion, causing the skill to activate when the user did not intend lead-mining or outbound-contact behavior. In this skill, unintended activation is more risky because later sections include contact extraction and automated outreach workflows, so a false trigger could expose sensitive trade-show queries or steer the agent into sales automation unexpectedly.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill describes automatic generation and sending of email or WhatsApp messages, plus follow-up after 48 hours, without a prominent upfront consent gate or clear user-facing confirmation immediately before sending. This is dangerous because an agent could perform external communications on behalf of a user, contact third parties without proper authorization, and create legal, reputational, and spam/compliance risk; the trade-lead context increases risk because it processes contact data at scale and explicitly optimizes outreach.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The skill states that outreach will be generated in multiple languages automatically, but it does not clearly ask the user to choose or confirm the language before composing or sending messages. This can lead to miscommunication, inappropriate localization, or sending outreach in a language the recipient does not expect, which is lower severity than autonomous sending itself but still increases compliance and reputational risk in a bulk lead-generation workflow.

Static analysis

No suspicious patterns detected.