Back to skill

Security audit

Xborder Ecom Guard - 跨境电商合规护栏

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese-language compliance text checker with no evidence of network access, persistence, credential use, or hidden side effects.

Reasonable to install for Chinese-language, local pre-publication checks of e-commerce copy. Treat results as heuristic flags, not legal advice or certification; verify current US/EU obligations and note the stray finance wording plus PRC disclaimer before relying on it in a formal workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring, CLI help text, and user-facing output are all hard-coded in Chinese, which imposes a specific language on users. The file does not offer any opt-in, localization switch, or justification that the tool is limited to a Chinese-speaking region or audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and detection logic are clearly scoped to cross-border e-commerce compliance terms, but the argparse description at L100 says "金融消保合规护栏检测内核" and the closing guidance at L136 references "持牌经营、风险揭示" obligations associated with financial compliance. This is an active contradiction in inline/documentation text about the skill's intent, not just an omission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file’s natural-language docstring, labels, and term list are entirely written in Chinese, and the stated scope targets US/EU cross-border e-commerce content without indicating that Chinese is optional or user-selected. That creates a language/locale policy concern because the skill appears to impose a specific language on a broad audience rather than offering opt-in or documenting a narrow, justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language content describing the skill is entirely in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language policy text states that the disclaimer is governed by and interpreted under the laws of the People's Republic of China. This imposes a specific legal/jurisdictional framework in the skill documentation despite the skill targeting US/EU cross-border compliance use cases, and it does not offer user choice or explain why this locale constraint is required for operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.