Back to skill

Security audit

抽奖工具 · 抽奖活动创建助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed LottoTool assistant that previews and confirms lottery activity changes before using an authorized MCP connection, with a privacy note around physical-prize fulfillment data.

Install only if you trust LottoTool/WorkBuddy with authority to create and edit lottery activities in the authorized account. For physical prizes, make sure your activity terms and privacy practices explain why recipient name, phone, and address are collected, who can access them, how long they are kept, and how they can be deleted.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The schema explicitly states that selecting `express` delivery causes collection of name, phone number, and address, but it provides no accompanying privacy notice, data-minimization guidance, retention limits, or consent requirements. In a lottery/marketing tool, this creates a real risk of over-collection or non-compliant handling of sensitive personal data because operators may enable physical prize fulfillment without understanding the privacy obligations.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.