Back to skill

Security audit

Food/Drug Cosmetics Ad Guard - 食药化妆品广告合规护栏

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese food/drug/cosmetics ad-compliance checker with no hidden access, though one CLI help label incorrectly mentions financial consumer protection.

Installers should understand that this is a narrow local keyword guard for Chinese/PRC advertising compliance, not legal advice or a complete approval workflow. The publisher should fix the financial-consumer-protection help text before relying on it operationally, but the inspected package does not show hidden data access, persistence, network activity, or system mutation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI metadata and user-facing guidance describe a different compliance domain ('金融消保') than the actual stated purpose of the skill. In a compliance guardrail, incorrect domain labeling can cause operators or downstream agents to apply the tool under the wrong legal/policy assumptions, leading to false trust, misrouting, or missed required review before publication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents policy and operational guidance inconsistent with the skill's declared scope, which is dangerous because this tool is meant to gate regulated advertising content. Incorrect policy framing can mislead users into thinking the guard has validated the right obligations, reducing scrutiny and potentially allowing unlawful medical, drug, or cosmetics advertising claims to be published.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and profile metadata describe the skill entirely in Chinese and scope it to Chinese advertising compliance content, but there is no natural-language indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a locale-policy concern unless the constraint is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file uses only Chinese text for the skill description and changelog, and does not state that the skill is intended exclusively for Chinese-speaking users or provide any language choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation appears to require Chinese comprehension throughout, but it does not mention that the skill is Chinese-language only or offer any user language choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as operating in that language, with no indication that users may choose another language or that the language restriction is an explicit opt-in. Under the stated policy, forced language or locale behavior should be documented or optional unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.