Back to skill

Security audit

1688 Product Find

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real 1688 product-search tool, but its credential setup can expose reusable AK/OAuth credentials in chat, command output, and local files.

Install only if you are comfortable granting this skill access to a 1688 AK and with it storing credentials locally. Avoid pasting real AK values into chat, do not run configure status with live credentials until redaction is fixed, prefer an isolated environment, and rotate any AK that appears in transcripts or logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/capabilities/configure/service.py:26
Finding

AK Signing Credential Is Stored with Ambient Permissions and Exposed Through Standard Output

Content
View full analysis
Tuple[bool, str]: """Write the AK to a local configuration file.""" try: CONFIG_PATH.parent.mkdir(parents=True, exist_ok=True) with open(CONFIG_PATH, "w", encoding="utf-8") as f: json.dump({"ak": api_key}, f, ensure_ascii=False, indent=2) return True, str(CONFIG_PATH) except Exception: return False, "" ``` The callback server returns the unmasked credential after storing it: ```python def _save_ak(self, ak: str) -> dict: from capabilities.configure.service import validate_ak, configure_ak is_valid, error_msg = validate_ak(ak) if not is_valid: return {"success": False, "error": "AK_INVALID", "error_description": error_msg} success, storage_location = configure_ak(ak) if success: return {"success": True, "ak": ak} return {"success": False, "error": "AK_SAVE_FAILED", "error_description": "AK save failed; check file permissions"} ``` The authorization process then emits the full AK to standard output: ```python if completed and server.success: ak = server.result.get("ak", "") _cleanup_pid() output_json({ "success": True, "markdown": "AK configured successfully", "data": {"ak": ak} }) return 0 ``` ### Technical Analysis The AK contains material from which the Access Key ID and signing secret are derived. It must therefore be handled as a reusable authentication credential. The configuration file is created with ordinary `open(..., "w")` behavior. No explicit `0600` mode is enforced, and the parent directory is not explicitly restricted. The effective permissions depend on ...[truncated 1591 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/encrypted_store.py:19
Finding

OAuth Tokens Are Stored as Plaintext JSON When the OS Keychain Is Unavailable

Content
View full analysis
dict[str, str]: if not ENCRYPTED_TOKEN_FILE.exists(): return {} try: raw = ENCRYPTED_TOKEN_FILE.read_text(encoding="utf-8") return json.loads(raw) except (json.JSONDecodeError, Exception) as e: logger.warning("Storage file read failed: %s; rebuilding", e) return {} def _save_store(data: dict[str, str]) -> None: json_bytes = json.dumps(data, ensure_ascii=False, indent=2).encode("utf-8") ENCRYPTED_TOKEN_FILE.parent.mkdir(parents=True, exist_ok=True) fd, tmp_path = tempfile.mkstemp( dir=str(ENCRYPTED_TOKEN_FILE.parent), prefix=".token_", suffix=".tmp", ) try: os.write(fd, json_bytes) os.close(fd) os.chmod(tmp_path, 0o600) os.replace(tmp_path, str(ENCRYPTED_TOKEN_FILE)) except Exception: try: os.close(fd) except OSError: pass if os.path.exists(tmp_path): os.unlink(tmp_path) raise ``` ```python def enc_store_token(key: str, value: str) -> None: store = _load_store() store[key] = value _save_store(store) logger.debug("Token written to file storage: key=%s", key) ``` ### Technical Analysis Despite the module name `encrypted_store`, the fallback serializes access tokens, refresh tokens, and associated metadata directly into JSON. No encryption or authenticated integrity protection is applied. The file is correctly assigned mode `0600`, which limits access by other operating-system users. However, file permissions do not protect tokens from compromise of the same user account, overly broad backup collection, workspace synchro ...[truncated 1167 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capabilities/link_search/service.py:167
Finding

TLS Certificate and Hostname Verification Are Disabled for Marketplace Page Retrieval

Content
View full analysis
str: """Retrieve page content.""" req = urllib.request.Request(url, headers=DEFAULT_HEADERS) ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE with urllib.request.urlopen(req, timeout=15, context=ctx) as response: content_encoding = response.headers.get('Content-Encoding', '') data = response.read() if 'gzip' in content_encoding: data = gzip.decompress(data) charset = 'utf-8' content_type = response.headers.get('Content-Type', '') if 'charset=' in content_type: charset = content_type.split('charset=')[-1].split(';')[0].strip() return data.decode(charset, errors='ignore') ``` ### Technical Analysis `ssl.create_default_context()` initially enables certificate-chain and hostname validation. The subsequent assignments explicitly disable both protections. Although incoming marketplace URLs are converted to canonical 1688, Taobao, or Tmall URLs before this request, disabling certificate verification allows an attacker controlling the network path, DNS resolution, proxy configuration, or a hostile access point to impersonate those hosts. The forged HTML is parsed for product image URLs. A network attacker can therefore influence the image URL submitted to the authenticated search gateway and manipulate the resulting product search. ### Attack Path 1. A user performs a link-based product search. 2. The Skill requests a canonical marketplace page over HTTPS with certificate and hostname validation disabled. 3. A network-positioned attacker intercepts the TLS connection and presents an arbitrary certificate. 4. The client accepts the certificate and receives ...[truncated 847 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
cli.py:38
Finding

Runtime Auto-Installation Uses Unbounded Dependencies Without Integrity Pinning

Content
View full analysis
None: """Detect core dependencies and automatically install requirements if absent.""" try: import requests return except ImportError: pass import subprocess req_file = str(SKILL_DIR / "requirements.txt") result = subprocess.run( [ sys.executable, "-m", "pip", "install", "-r", req_file, "-q", "--disable-pip-version-check", ], capture_output=True, text=True, ) if result.returncode != 0: print(json.dumps({ "success": False, "error_code": "DEPS_INSTALL_FAILED", "markdown": ( "Dependency installation failed. Run manually:\n\n" f"```\npip install -r {req_file}\n```\n\n" f"{result.stderr.strip()}" ), }, ensure_ascii=False), flush=True) sys.exit(1) _ensure_deps() ``` The dependency declarations are not exact or hash-pinned: ```text requests>=2.28.0 keyring>=25.0 Pillow>=10.0.0 ``` ### Technical Analysis Any invocation of the CLI can initiate a package installation when `requests` is unavailable. Installation uses the environment's configured Python package index and resolver behavior. The requirements specify only minimum versions. Consequently, future versions automatically satisfy the constraints, and there is no cryptographic hash verification of downloaded artifacts. A compromised package release, hostile package index, resolver manipulation, or poisoned mirror could cause unreviewed code to be installed and executed with the Agent process's privileges. The sentinel check only tests `requests`. A partially confi ...[truncated 1233 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/callback_server.py:147
Finding

Loopback OAuth Mutation Endpoints Lack a Request-Bound Authentication Secret

Content
View full analysis
dict: if self._exchange_result is not None: return self._exchange_result if not self._code_verifier: result = {"success": False, "error": "code_verifier already used; reauthorize"} self._exchange_result = result return result request_body = { "clientId": self.client_id, "redirectUri": self.redirect_uri, "code": code, "codeVerifier": self._code_verifier, } body_str = json.dumps(request_body) self._code_verifier = None ``` The exchange endpoint accepts requests with no `Origin` header and does not require a session secret: ```python def _handle_exchange(self): origin = self.headers.get("Origin", "") allowed = f"http://localhost:{server_ref._port}" allowed2 = f"http://127.0.0.1:{server_ref._port}" if origin and origin not in (allowed, allowed2): self._send_json(403, {"success": False, "error": "CORS_DENIED"}) return content_length = int(self.headers.get("Content-Length", 0)) body = json.loads(self.rfile.read(content_length)) if content_length > 0 else {} code = body.get("code", "") if not code: self._send_json(400, {"success": False, "error": "MISSING_CODE"}) return result = server_ref._exchange_token(code) server_ref._result = result if result.get("success"): server_ref._success = True self._send_json(200, result, cors_origin=origin or allowed) ``` The AK mutation endpoint has the same weakness: ```python def _handle_save_ak(self): origin = self.headers.get("Origin", "") allowed = f" ...[truncated 3641 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (187)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication, token refresh/revoke, and authorization-scope validation are privileged account-management actions beyond the stated sourcing workflow. This hidden expansion of capability can expose credentials and permit account-affecting operations without reviewers understanding the full trust model.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
| `SKILL.md` | 主文件 | 技能入口、意图判断、工作流、错误处理 |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions tell the agent to ask the user to provide their AK manually in chat, but do not warn that this is sensitive credential material. Collecting secrets through conversational channels is dangerous because chats may be retained, reviewed, exported, or visible to other tools, resulting in credential leakage and potential account misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The status output explicitly includes the configured AK value, which can disclose a live credential into chat transcripts, logs, screenshots, or downstream monitoring systems. Exposing a reusable API secret materially increases the risk of unauthorized API use, account abuse, and lateral compromise of related resources.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_auth.py (reported line 130)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 27)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Injecting parsed .env entries into os.environ at module load time can expose unrelated secrets and alter runtime behavior for the rest of the process. This is especially risky because it happens implicitly and globally, making accidental downstream leakage or misuse more likely even if this module only intends to use three metadata fields.

Content

Scanner excerpt · scripts/_tracker.py (reported line 43)May include surrounding context.

python
os.environ[key] = value


# 模块加载时解析一次 .env
_load_env_file()

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements full OAuth 2.1 and AK credential acquisition flows, including opening a browser, starting a local callback server, and returning acquired credentials. That is materially broader than the declared product-finding skill purpose, so it introduces privileged authentication capability that could be abused to obtain or reuse account access beyond simple product search.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AK mode is especially sensitive because it acquires and returns an access key-like credential directly via the callback flow, then emits it in JSON output. For a product-search skill, exposing a raw credential acquisition path is hard to justify and increases the risk of credential harvesting, misuse by downstream components, or accidental logging/leakage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements a local OAuth/AK callback server, token exchange, and credential handling that are unrelated to the declared product-finding/search purpose of the skill. Capability mismatch is a strong risk signal because it expands the trust boundary to authentication and secret management; a shopping/search skill should not silently introduce local credential capture and token persistence behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code validates and stores an AK locally via configure_ak(), which gives the skill credential-management capability not justified by its stated shopping/search purpose. Unnecessary secret ingestion and persistence increases the chance of credential theft, misuse, or later abuse by other components, especially when tied to a local callback flow that can accept values from browser-driven requests.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/_auth.py:136

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/callback_server.py:211

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/token_manager.py:53

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/capabilities/link_search/service.py:174