Back to skill

Security audit

查询微信Unionid关联的京东账号及基础信息

Security checks across malware telemetry and agentic risk

Overview

The skill is a simple lookup, but it exposes sensitive account-linkage and full account details without built-in limits or safeguards.

Install only in an environment where database access is already governed by approved support, fraud, or compliance workflows. Users should add or require authorization checks, query logging, masking, and field minimization before allowing agents to run this against real account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This skill enables lookup of linked payment PIN, login PIN, and full JD account base information from a WeChat unionid, but provides no authorization checks, purpose limitation, masking, or warning about the sensitivity of the operation. In this context, the lack of safeguards materially increases the risk of privacy violations, account correlation, insider abuse, and overbroad disclosure of personal data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.