Back to skill

Security audit

差评管家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language review-reply drafting aid that does not install code, access accounts, or auto-publish content.

Before installing, expect this skill to work best for Chinese merchant review workflows. Review any customer data before sharing it with your agent, and manually check all public reply drafts before posting, especially safety, legal, refund, or complaint-related cases.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The README presents all user-facing instructions and examples exclusively in Chinese, which can amount to a language policy violation when no user language preference or alternative is offered. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific compliance reason.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The description states "本技能面向中文评价设计," which sets a language-specific constraint in the skill's natural-language behavior. Under the policy rule, forcing a specific language or locale without opt-in can be a violation unless clearly documented as a justified region-specific constraint.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This markdown file contains user-facing natural-language guidance exclusively in Chinese, with no indication that users may select another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The entire template is written as a prescriptive Chinese response framework for ecommerce review handling, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Static analysis

No suspicious patterns detected.