Back to skill

Security audit

1688 Marketing

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fits its 1688 marketing purpose, but its local authorization server and credential storage create account and credential risks that need review.

Install only if you are comfortable with this skill managing 1688 credentials locally. Use it on a trusted machine and network, avoid shared workspaces or backups for .1688-AK and .1688-oauth, prefer an OS keychain-backed environment, and review credential reset, clear, and status behavior before using it for business account operations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/callback_server.py:177
Finding

Network-Exposed Callback Server Allows Unauthenticated AK Replacement and Shutdown

Content
View full analysis
None: """Linux/macOS:单 AF_INET6 dual-stack socket,IPV6_V6ONLY=0 同时接受 IPv4/IPv6。 必须在 server_bind() 之前设置 IPV6_V6ONLY,故使用 bind_and_activate=False 延迟绑定。 """ self._server.server_close() self._server = _ThreadingHTTPServerIPv6(("::", port), handler, bind_and_activate=False) self._server.socket.setsockopt(socket.IPPROTO_IPV6, socket.IPV6_V6ONLY, 0) self._server.server_bind() self._server.server_activate() self._thread = threading.Thread( target=self._server.serve_forever, daemon=False, name="oauth-callback-server", ) self._thread.start() logger.debug("Unix: dual-stack 回调服务器启动在 [::]:%d(同时接受 IPv4/IPv6)", port) ``` The credential-saving endpoint permits requests with no `Origin` header and does not require the generated OAuth state or another secret: ```python def _handle_save_ak(self): origin = self.headers.get("Origin", "") allowed = f"http://localhost:{server_ref._port}" allowed2 = f"http://0.0.0.0:{server_ref._port}" if origin and origin not in (allowed, allowed2): self._send_json(403, {"succe ...[truncated 3911 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capabilities/configure/service.py:42
Finding

AK Storage Uses Weak Device-Derived Encryption and Does Not Enforce Restrictive File Permissions

Content
View full analysis
bool: """将 AK 加密后存储到 ak_store 文件""" try: encrypted = _encrypt(ak) AK_STORE_FILE.parent.mkdir(parents=True, exist_ok=True) with open(AK_STORE_FILE, "w", encoding="utf-8") as f: json.dump({"ak": encrypted}, f, ensure_ascii=False) return True except Exception: return False ``` On Linux, the encryption key is derived from a generally readable machine identifier: ```python else: for path in ("/etc/machine-id", "/var/lib/dbus/machine-id"): try: mid = Path(path).read_text().strip() if mid: logger.debug("Linux: 使用 %s 作为设备 ID", path) return mid except Exception: pass return _get_or_create_fallback_id() ``` That identifier is used directly as the PBKDF2 input: ```python def encrypt_ak(plaintext: str, machine_id: str | None = None) -> str: """加密 AK,返回 'v1:' 格式字符串。""" mid = machine_id or _get_machine_id() kdf_salt = os.urandom(_SALT_LEN) nonce = os.urandom(_NONCE_LEN) key = derive_key(mid, kdf_salt) raw = plaintext.encode("utf-8") ciphertext = _xor(raw, _keystream(key, nonce, len(raw))) mac = _hmac.new(key, kdf_salt + nonce + ciphertext, hashlib.sha256).digest() blob = base64.b64encode(kdf_salt + nonce + mac + ciphertext).decode("ascii") return _PREFIX + blob ``` ### Technical Analysis The storage routine creates the parent directory with process-default permissions and writes `.ak_store.json` without calling `chmod`, setting a restrictive creation ...[truncated 2275 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/encrypted_store.py:48
Finding

OAuth Fallback Store Writes Access and Refresh Tokens as Plaintext JSON

Content
View full analysis
None: if is_keychain_available(): try: keyring.set_password(KEYCHAIN_SERVICE, key, value) logger.debug("Token 已写入 Keychain: key=%s", key) return except keyring.errors.KeyringError as e: error_msg = str(e) logger.error("Keychain 写入失败: %s", error_msg) if "-67674" in error_msg or "permission" in error_msg.lower(): raise KeychainError( "macOS Keychain 权限被拒绝。请在系统弹出的对话框中点击「始终允许」。" ) from e raise KeychainError(f"Keychain 写入失败: {error_msg}") from e _enc_store()(key, value) ``` The file backend serializes the supplied values directly to JSON: ```python def _save_store(data: dict[str, str]) -> None: json_bytes = json.dumps(data, ensure_ascii=False, indent=2).encode("utf-8") ENCRYPTED_TOKEN_FILE.parent.mkdir(parents=True, exist_ok=True) fd, tmp_path = tempfile.mkstemp( dir=str(ENCRYPTED_TOKEN_FILE.parent), prefix=".token_", suffix=".tmp", ) try: os.write(fd, json_bytes) os.close(fd) _set_file_permissions(tmp_path) try: os.rep ...[truncated 3048 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (167)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Refreshing and revoking tokens, clearing local auth state, and validating scopes are powerful authentication-management actions omitted from the declared purpose. If exploited or accidentally invoked, they could disrupt user access, alter authorization state, or expose sensitive auth workflows under a misleadingly benign label.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli.py (reported line 313)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli.py (reported line 317)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_const.py (reported line 77)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/token_manager.py (reported line 104)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_const.py (reported line 100)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 27)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能清单将该技能描述为用于 1688 招商活动查询、建议价查询、活动报名和商机推荐等营销操作,但此文件实际实现了本地 OAuth 回调处理、Token 交换、AK 保存以及将访问凭证写入本地存储。这不是简单的底层 HTTP 实现细节,而是独立的认证与凭证管理能力,明显超出清单中声明的业务功能范围。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a 1688 marketing skill for activity signup, recommended pricing, and opportunity queries, but this file implements local AK configuration, reset/clear, and OAuth token revocation. Credential-management operations are materially different from the declared merchant marketing workflows and expand the skill beyond its stated user-facing purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The module explicitly falls back to storing tokens and metadata in a local JSON file when the OS keychain is unavailable. Even with 0o600 permissions, this weakens credential protection because secrets are kept unencrypted at rest and may be recoverable by local compromise, backup exposure, container escape, or misconfigured Windows ACL handling; in a marketing skill that likely handles account tokens, this increases the risk of account takeover or unauthorized business actions.

Content

Scanner excerpt · scripts/encrypted_store.py (reported line 4)May include surrounding context.

python
"""
文件存储后端

当 OS Keychain 不可用时(如沙箱环境),将 Token 和元数据
存储在本地 JSON 文件中。

文件权限设置为 0o600(仅文件所有者可读写)。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_const.py (reported line 99)May include surrounding context.

python
"""
.env 文件原子读写器
保留非 OAUTH_1688_ 前缀的变量,仅更新 Token 相关变量
"""
from __future__ import annotations

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_const.py (reported line 105)May include surrounding context.

python
"""
.env 文件原子读写器
保留非 OAUTH_1688_ 前缀的变量,仅更新 Token 相关变量
"""
from __future__ import annotations

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 8)May include surrounding context.

python
"""
.env 文件原子读写器
保留非 OAUTH_1688_ 前缀的变量,仅更新 Token 相关变量
"""
from __future__ import annotations

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/_const.py:106

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/callback_server.py:284

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/token_manager.py:53