Back to skill

Security audit

Ecommerce Content Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local generator for Chinese ecommerce/social recommendation copy, with no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install this if you want Chinese-language ecommerce and social platform copy generation. Review generated promotional or review-style text for truthfulness and platform compliance before publishing, especially where it implies real usage or endorsement.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing title, description, features, and usage examples are all presented in Chinese, with no indication that other languages are supported or that the user may choose their preferred language. This can violate language/locale policy where skills must not impose a specific language unless the constraint is explicit and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file describes usage with generic phrases like "生成种草文案" and "生成朋友圈文案" without defining a bounded trigger list, activation context, or exclusion cases. These phrases are common natural-language requests in the skill's language domain and could overlap with ordinary conversation, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file labels the skill as a Chinese-language content generator and all generated copy is written in Chinese for platforms like 小红书、抖音、朋友圈、知乎. This imposes a specific language/locale by default with no opt-in, choice, or documented region-specific justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The comment at L064-L066 describes the method as generating '种草文案' (promotional seeding copy), which aligns with Xiaohongshu/Douyin/Moments marketing content. However, the dispatcher at L070-L075 also routes to generateZhihu, which produces a more review/Q&A-style answer format rather than the promotional copy implied by the docstring.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.