Back to skill

Security audit

Retail Digital Ai Expert 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This is a broad retail consulting skill with no executable code or hidden data movement, but users should apply separate privacy controls before using its customer, employee, or financial data templates.

Install only if you want a broad retail digital-transformation consulting assistant. Before pasting real client, customer, member, employee, financial, or system data into it, anonymize or aggregate the data, confirm you have authorization to use it, and add your own privacy, retention, access-control, and legal-review steps for CDP, OneID, employee monitoring, cross-border data, and AI personalization work.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises extremely broad trigger coverage ('150+' keywords across many retail and adjacent technology terms), which increases the chance of unintended activation in conversations that only loosely match the domain. This can cause prompt hijacking of unrelated tasks, override user intent, and make downstream behavior less predictable because the skill may engage in contexts where its constraints and output mandates are inappropriate.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The positioning claims the skill can answer 'any time, any retail format, any digital problem,' which is effectively always-applicable activation language. In practice, such universal framing encourages the assistant to apply this skill outside its safe scope, increasing the risk of context takeover, misrouting, and irrelevant instruction injection into normal user interactions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description is extremely broad, advertising coverage across nearly every retail business model, business function, and technology stack without any visible activation boundaries or task-scoping constraints. This increases the chance the skill will be invoked in unintended contexts, produce over-authoritative guidance outside its safe scope, or overshadow more appropriate specialized skills, which can lead to unsafe or low-quality decisions in enterprise environments.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The case study promotes CDP+OneID identity unification and automated customer profiling/marketing across online and offline channels, but provides no warning about consent, lawful basis, data minimization, retention, or cross-channel identity matching risks. In a retail transformation skill, this can normalize privacy-invasive implementations and lead operators to merge identifiers and activate marketing automation in ways that violate customer expectations or applicable privacy rules.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document explicitly frames enterprise-controlled WeCom relationships as a way to retain customer access after staff departure, without any caution about customer consent, transparency, access governance, or misuse of personal relationship data. This is dangerous because it encourages organizational capture and reassignment of customer communications as an operational best practice, which can enable unauthorized access, intrusive outreach, or non-compliant employee/customer data handling.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The document promotes AI personalization and multilingual content generation at global scale without any mention of customer notice, consent basis, data minimization, or safeguards for profiling. In a retail transformation skill, this can normalize deploying customer-data-driven AI features without addressing privacy expectations or regulatory obligations, especially when recommendation systems may process behavioral data across channels and regions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The data flywheel section describes aggregating global store data into a real-time lake and training global AI models, but omits warnings about cross-border transfer, jurisdictional restrictions, governance, and access controls. In a 32-country retail setting, this omission is risky because readers may treat unrestricted global data centralization as a best practice, leading to noncompliant transfers or overcollection of personal and operational data.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The template explicitly centralizes detailed store operations and member data at headquarters, but provides no guidance on privacy notices, lawful basis, access controls, retention, or tenant separation between franchisor and franchisees. In a retail franchise context, this can lead to over-collection, misuse of customer/member data, unauthorized internal access, and noncompliance with privacy and data protection obligations.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The AI diagnosis and real-time alerting sections promote continuous automated analysis of operational and potentially sensitive business data without warning about accuracy limits, false positives, operational disruption, or exposure through notifications and reports. Because this skill is a transformation template intended for broad deployment across franchise stores, the omission is more dangerous: users may implement monitoring and AI recommendations at scale without safeguards, access restrictions, or human review.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The template explicitly promotes continuous tracking of individual employee usage, non-usage, and error behavior through daily reporting, but it does not include any privacy notice, lawful-basis guidance, data minimization limits, or safeguards against punitive misuse. In a workplace context, this can lead to undisclosed employee surveillance, excessive collection of performance data, and compliance risk under labor, privacy, or monitoring laws, especially if deployed across many stores and staff.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The assessment template explicitly solicits sensitive business and operational information such as annual revenue, IT budget, store count, and current system inventory, but provides no data minimization, confidentiality, retention, or handling guidance. In a consulting-style skill, this can lead users to paste commercially sensitive data into the agent or downstream systems, increasing risk of unnecessary exposure, leakage, or policy noncompliance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The README maps very broad, natural user phrases like '我们想做AI' or '系统要上线了怎么办?' directly to workflow entry points, which can cause unintended or over-broad workflow invocation. In an agent skill, ambiguous triggers increase the chance that ordinary conversational text activates heavyweight guidance or the wrong phase, leading to mis-scoped actions, misleading recommendations, or unsafe automation chaining.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This workflow explicitly instructs collection of financial, operational, product, membership, and system data over 12 months, including CRM-derived member metrics, but provides no privacy, consent, minimization, or handling guidance. In a consulting or AI-assisted workflow, that omission can lead users to aggregate sensitive business and customer data into prompts, documents, or tools without appropriate safeguards, increasing risk of privacy violations, over-collection, and unauthorized disclosure.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow directs collection of sensitive business and potentially personal data, including financial records, membership metrics, system inventories, and organizational details, but provides no instructions for lawful basis, minimization, secure transfer, retention, or access control. In a consulting skill for digital transformation, this omission increases the chance of over-collection, unauthorized exposure, and mishandling of confidential client and customer data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The store-visit guidance encourages gathering employee quotes and probing about customer WeChat contacts and frontline practices without any mention of notice, consent, minimization, or anonymization. This can lead to unnecessary collection of personal data and employee/customer-identifiable information during observational research, especially in physical retail settings where sensitive context is easy to capture informally.

Static analysis

No suspicious patterns detected.