Back to skill

Security audit

1688-item-title-optimizer

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to optimize 1688 product titles, but it should be reviewed because it uses a merchant access key and defaults to operating across every bound shop when a shop is not specified.

Install only if you expect this skill to use a 1688 merchant access key, contact gateway.1688.com, retrieve bound-shop metadata, and run title optimization across every bound shop unless you explicitly specify one. Prefer scoping each request to a named shop/loginId, review telemetry expectations, and confirm carefully before allowing any external one-click title update.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Returning store/account binding information and loginId lists is broader than the declared title-rewrite purpose. Even if used operationally, exposing such metadata without clear disclosure can leak organizational structure and facilitate unintended cross-tenant access patterns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly describe side-effecting actions such as writing selected data directly to a database, creating purchase orders, re-running searches with changed criteria, and blacklisting items. These operations are far outside the justified context of title optimization and could cause unauthorized business changes if an agent treats these examples as available patterns to emulate.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation describes immediate order creation using a default shipping address and placing the order into a payment workflow without an explicit safety warning or confirmation step. This is a high-risk transactional side effect that is completely unrelated to title optimization and could produce financial loss, operational disruption, or accidental procurement if followed by an agent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 8)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-item-title-optimizer
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 26)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-item-title-optimizer
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 42)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-item-title-optimizer
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 27)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a CLI for configuring and validating an access key, which is outside the declared purpose of a title-optimization skill. In an agent-skill context, unexpected credential-management functionality materially increases risk because it can be used to solicit, process, or retain sensitive secrets without clear user expectation or business justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though it uses environment variables, file reads, and network access. This weakens platform enforcement and reviewer visibility, making it easier for the skill to access credentials and external endpoints beyond what a user would infer from a title-optimization tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases increase the chance the skill activates on ambiguous everyday language. In this skill's context, accidental activation is more dangerous because it can lead to shop enumeration, credential-dependent API use, and exposure of merchant data beyond the user's intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates enumerating all bound shops and operating across them by default when the user does not specify a shop. That creates an unsafe default that can unnecessarily process and surface data from unrelated shops, violating least surprise and increasing cross-tenant exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document does not prominently warn users that the default behavior is to traverse all bound shops. Missing disclosure undermines informed consent and makes accidental bulk cross-shop processing more likely in a sensitive merchant-management context.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Default cross-store enumeration and execution can expose titles, item IDs, and other shop-linked metadata in aggregated results from stores the user did not explicitly choose. In a multi-tenant commerce environment, that context makes the issue materially more dangerous because it breaks expected data scoping boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all user-facing instructions, parameters, errors, and display requirements only in Chinese. The policy calls for flagging language or locale constraints when a specific language is forced without user opt-in, and no alternative language option or justification is provided here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames the skill as focused on optimizing 1688 product titles, but the CLI documentation and command discovery expose additional commands such as configure, get_keyword_info, and get_tokenizers. Those capabilities go beyond the stated optimization-focused behavior and indicate the skill does more than the manifest description claims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code scans capabilities/*/cmd.py and registers every discovered command at runtime, rather than limiting execution to known title-optimization functions. This makes the effective behavior of the skill broader than the manifest's described purpose, because any additional capability module placed in that directory becomes part of the exposed skill surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The CLI reports telemetry after every command execution via report_skill_usage() without any visible notice, consent flow, or opt-out in this file. Silent telemetry can expose usage patterns and potentially sensitive operational metadata, which is more concerning in a skill handling user-provided product titles and optimization requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.