Back to skill

Security audit

Product Reverse Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain Markdown guide for analyzing product screenshots, with no executable code or hidden install behavior, but it should be used carefully with sensitive screenshots.

Install only if you want a Chinese-language product screenshot analysis workflow. Avoid using it on confidential internal interfaces unless you are comfortable with an MD report being created, and confirm where the report will be saved before running it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description contains multiple broad trigger phrases such as requests to 'analyze this product' or infer design logic from screenshots. In agent routing systems, overly broad natural-language activation criteria can cause unintended invocation on common user requests, exposing screenshots or product-analysis tasks to a specialized workflow without clear user intent. The skill context increases risk because it is designed to infer business flows and architecture from screenshots, which may encourage analysis of sensitive internal interfaces or competitor products when triggered too loosely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating Chinese output without user choice can override the user's preferred language and reduce transparency, especially if the surrounding system or user expects another language. While not a direct code-execution issue, hardcoded language constraints can impair informed review of sensitive analysis results and create usability or policy-compliance problems in multilingual environments. The skill context makes it somewhat more concerning because the output may include nuanced risk, architecture, or compliance observations that should be readily understandable to the requesting user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to save analysis results as an MD file introduces an implicit persistence or file-write side effect without any notice, consent, or scope limitation. In an agent environment, silent file creation can leak sensitive inferences about uploaded screenshots, create unexpected artifacts, or persist proprietary analysis beyond the user's expectations. The context makes this more dangerous because the output may contain inferred business logic, architecture details, and competitive intelligence derived from potentially confidential UI images.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.