Back to skill

Security audit

1688竞店竞品分析

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a 1688 competition-analysis purpose, but it exposes an overbroad raw merchant-data query path under the logged-in shop session.

Install only if you are comfortable letting the skill read sensitive 1688 merchant analytics for the currently authorized shop. The main risk is the raw query capability: it should ideally be restricted to documented competition and customer-loss endpoints before use in a shared or high-trust environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (72)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose is a bounded competitor-analysis workflow, but the skill also exposes a generic raw-query mechanism that accepts configurable data source, API path, and parameter JSON. This materially broadens the accessible data surface beyond the declared use case and can be abused to query additional merchant data or endpoints under the current logged-in session.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill invokes shell commands, performs file reads, and can access network-backed merchant data, but it declares no explicit tool scope or permissions boundary. That creates an authorization ambiguity where the runtime may grant broader capabilities than the skill’s stated business purpose, increasing the chance of unintended data access or command execution paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists trigger phrases such as “对标” and “对手”, which are generic terms that can appear in ordinary business conversation outside the intended narrow skill scope. The file does not provide exclusion conditions or negative examples to bound when these triggers should or should not invoke the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction says the skill should act when the user raises competition-related questions, followed by a wide list of example topics, but it does not clearly distinguish covered requests from adjacent general analysis or strategy questions. Without tighter boundaries, ordinary discussion about competitors or benchmarking may unintentionally trigger the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file states “中文输出:禁止使用英文指标名”, which imposes a language requirement on user-visible output. There is no opt-in, user language selection, or documented locale-specific justification showing that Chinese-only output is required for this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L0003 明确写明“所有接口均为 GET”,形成了该技能接口行为的总述性承诺。但在 L1039-L1040 又定义 /item/customerLoss 使用 POST,与前述总述直接矛盾。这会误导实现方或审计方对技能实际调用行为的理解。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The document explicitly relies on same-origin Cookie authentication for sensitive shop analytics APIs. In a skill context, instructing agents to operate against authenticated browser/session state increases the chance that privileged merchant data is accessed via ambient credentials rather than a tightly scoped token flow, which is dangerous if the skill is misused or if execution escapes the intended environment.

Content

Scanner excerpt · references/api/compete-api.md (reported line 6)May include surrounding context.

md
> 站点:`https://sycm.1688.com/ms/compete/*`,所有接口均为 GET,同源 Cookie 鉴权,URL 末尾 `_` 为防缓存时间戳。指标类字段多为「指数」而非绝对值,返回结构常见 `{value, cycleCrc}`(cycleCrc = 环比变化率)。

> ⚠️ **经 AK 网关(`query_shop_data`,dataSource=SYCM)调用本文档接口的须知**:
> - `apiPath` 取接口地址 `/ms/` 之后、去 `.json` 的部分(如 `compete/competeShop/shopList`)。
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 10)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 11)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 14)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 185)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 190)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 191)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 210)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 234)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 235)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 239)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 243)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 310)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api/compete-api.md (reported line 315)May include surrounding context.

md
> - **本文档所有入参示例已按网关要求标注为大写枚举**(dateType:`RECENT_1`/`RECENT_7`/`RECENT_30`/`MONTH`;device:`ALL`/`PC`/`WIRELESS`),**直接照抄即可、无需再转化**。网关对原站小写值(recent7/day/0)会**静默失败**(`success:true` + `data:null`,不报错);仅当经浏览器直连 sycm 原站调用时,才需换回原站小写值。`dateRange` 照文档原样传。
> - 返回字段名被网关**汉化**(`memberId`→`会员ID`、`offerId`→`商品ID`、`ipvUvIndex`→`流量指数`、`seUvIndex`→`搜索指数`、`payOrdAmtIndex`→`交易指数`、`buyerIndex`→`买家指数`、`statDate`→`时间` 等),解析时以实际返回为准,本文档英文出参名仅供语义对照。
> - memberId 类参数用 `getShopMonitorInfo` 返回的字符串;`ipvUvSourceV2` 的 `offerId1` 必须是本店商品(否则返 1001「您无权查询该商品数据」)。
> - `getLossTopShopList`(客户流失榜)日粒度数据有延迟:查昨天返空数组 `[]` 时,用 `dateType=RECENT_1` + `periodsAgo=1` 回溯前一天即可取到;该接口不支持 RECENT_30 长窗口(返空)。
> - ⚠️ **三个流失类接口经网关只支持日粒度**:`getLossTopShopList`、`searchLossOffer/getOfferList`、`viewLossOffer/getOfferList` 传 `RECENT_7` / `RECENT_30` 均返 **`recordCount=0`(空壳,不报错)**,必须用 **`dateType=RECENT_1` + `dateRange` 单日 + `periodsAgo=1`**(回溯前一天)才有数据。**切勿因 recordCount=0 就判定“无流失数据”**。
> - 流失类接口返回 key 也被汉化且与文档英文名差异较大:`searchLossOffer` 为 `竞品平均搜索引导访客数` / `搜索竞争商品数` / `本店商品搜索引导访客数` / `本店商品搜索引导支付买家数`;`viewLossOffer` 为 `流失率` / `流失金额` / `流失人数`。
> - ⚠️ **`ipvUvSourceV2` 双列字段命名不对称**:竞品侧带 `first` 前缀(`firstOffer访客数`、`firstOffer支付金额`、`first下单买家数`、`firstInquiry指数值`),但**本店侧的访客数与支付金额无 `my` 前缀**,直接叫 `访客数` / `支付金额`(仅 `my下单买家数` / `myInquiry指数值` / `my有效询盘用户数` 带 my 前缀)。**按 `my*` 前缀扫字段会把本店访客/成交全读成空**,造成“本店无流量”误判;另外节点名为 `流量来源名称`(非 `outerName`)、层级为 `来源层级`、父节点为 `流量父来源ID`。

Static analysis

No suspicious patterns detected.