Back to skill

Security audit

查询京东账号(京东Pin)的手机号解换绑

Security checks across malware telemetry and agentic risk

Overview

This skill is a plain workflow document, but it directs agents to correlate a JD account with phone, employee, and company records without stated authorization or privacy controls.

Install only in an environment where users are authorized to access these internal JD datasets and where approvals, logging, masking, and purpose limits are enforced outside the skill. Do not use it for general account lookup without a verified business need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs retrieval of bound phone numbers, employee ERP identities, and linked company information from an account identifier, but provides no warning, authorization gate, purpose limitation, or privacy handling requirements. This creates a clear risk of unauthorized access, insider misuse, and privacy violations involving sensitive personal and employment data.

Ssd 3

High
Confidence
99% confidence
Finding
The workflow is designed to correlate a JD account PIN with historical bound phone numbers, employee records, and company/vendor relationships across multiple internal tables. This cross-dataset enrichment materially increases the sensitivity of the operation and enables deanonymization, profiling, and potential targeting of individuals or associated companies if used without strict controls.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.