Back to skill

Security audit

1688-shop-daily-report

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real 1688 shop daily-report skill, but it has broader access to shop data and possible AK-bearing bind-list data than the report itself clearly needs.

Install only if you are comfortable giving this skill access to your 1688 AK and allowing it to read business, advertising, buyer, review, and bound-shop data across your shops. Before approval, the publisher should ideally strip any AK fields from bind-list outputs and constrain the free-query APIs to documented read-only report endpoints.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (85)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
声明描述的是一个面向业务分析的日报技能,核心能力应围绕拉取店铺数据、汇总分析并输出日报内容。实际提供的代码仅是认证层工具函数,负责解析 AK、读取环境变量 ALI_1688_AK、生成带签名的请求头,并未体现任何店铺经营日报相关的数据查询、分析、提醒或报告生成逻辑。虽然认证模块可能是实现日报功能的支撑细节,但就该代码片段本身而言,其实际行为与声明的业务能力明显不一致,且声明未提及凭证处理与签名认证这一实际能力,因此应判定为不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The declared purpose focuses on producing 1688 store operation daily reports with analytics and recommendations. The actual code does not compute, fetch, analyze, or present any shop business data, traffic data, user analysis, anomalies, or suggestions. Instead, it performs an unrelated tracking function: loading environment variables and sending a usage report to an API endpoint. This is a materially different primary purpose and an undeclared external communication capability. While telemetry can be a supporting implementation detail at the application level, this specific code chunk itself does not implement the described reporting behavior at all, so for this chunk there is a clear description-behavior mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
声明描述的是一个面向业务报表的‘店铺经营日报’技能,核心能力应是围绕日期生成日报内容并做分析解读。代码却只是底层数据采集工具:解析命令行或文件输入的查询配置,校验 AK,从多个店铺并发请求任意数据源/API 路径,并按店铺归档返回结果。虽然这种查询能力可能可作为日报生成的支撑组件,但从该代码片段本身看,主功能与声明的最终用户能力明显不一致,且缺少日期处理、日报结构化输出、异常检测和经营建议等关键行为,因此属于明显描述-行为不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The declared description is about generating a 1688 store operations daily report with analytics and recommendations. The supplied code does something entirely different: it is a command-line utility for configuring an AK credential, including checking existing config, validating input, saving it, and reporting success/failure. This is a materially different primary purpose and introduces an undeclared capability around credential/config management. The behavior is unrelated to the declared reporting functionality and trigger terms, so this is a clear mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The declared description is about producing a 1688 shop operations daily report with business/traffic/user analytics and recommendations. The supplied code does none of that. Instead, it is a configuration helper for access keys: validating string format, saving a key to an environment variable, and checking whether one exists. This is a materially different primary purpose and an undeclared capability related to credential/config management. Therefore the description does not accurately represent the code chunk.

Ae1

High
Category
analysis-evasion
Content
> 🧩 **本 Skill 已 workflow 化**。标准日报链路由 [`workflow/1688-shop-daily-report.js`](./workflow/1688-shop-daily-report.js) 编排执行(意图识别 → 日期解析 → 单店/多店子图 → 行动选择);本文档是 **work
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- **禁止暴露内部技术术语与实现细节**:如 `Profile`、`factory.md` / `trader.md` / `integrated.md` 等模板文件名、`loginId`、`GMV`、`UV`、`PV`、`get_multi_shop_report` / `multi_shop_report` 等命
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- **禁止暴露内部技术术语与实现细节**:如 `Profile`、`factory.md` / `trader.md` / `integrated.md` 等模板文件名、`loginId`、`GMV`、`UV`、`PV`、`get_multi_shop_report` / `multi_shop_report` 等命
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- **禁止暴露内部技术术语与实现细节**:如 `Profile`、`factory.md` / `trader.md` / `integrated.md` 等模板文件名、`loginId`、`GMV`、`UV`、`PV`、`get_multi_shop_report` / `multi_shop_report` 等命
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
ir}/references/interaction-specs.md`,随后触发 `select_action` 交互。**在两段内容都输出之前,禁止加载 `interaction-specs.md`、禁止触发 `select_action`、禁止弹出任何确认/选择卡片**
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
核心指标中文名 ↔ API 字段对照见 `capabilities.md`;常用派生指标:老客占比 = 老买家数/(新买家数+老买家数)、询盘转化率 = 订单量/询盘数×100%、动销率 = pullSalesItemCnt/itemCnt×100%、复购率取补充查询 overview 的 `oldCustomerPu
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
核心指标中文名 ↔ API 字段对照见 `capabilities.md`;常用派生指标:老客占比 = 老买家数/(新买家数+老买家数)、询盘转化率 = 订单量/询盘数×100%、动销率 = pullSalesItemCnt/itemCnt×100%、复购率取补充查询 overview 的 `oldCustomerPu
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
核心指标中文名 ↔ API 字段对照见 `capabilities.md`;常用派生指标:老客占比 = 老买家数/(新买家数+老买家数)、询盘转化率 = 订单量/询盘数×100%、动销率 = pullSalesItemCnt/itemCnt×100%、复购率取补充查询 overview 的 `oldCustomerPu
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- **实现位置**:`scripts/_tracker.py` → `report_skill_usage()`,在 `cli.py` 的 `main()` 中每次命令执行后自动调用
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- **实现位置**:`scripts/_tracker.py` → `report_skill_usage()`,在 `cli.py` 的 `main()` 中每次命令执行后自动调用
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Credential Access

High
Category
Privilege Escalation
Content
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-shop-daily-report
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-shop-daily-report
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-shop-daily-report
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhubai
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest describes a skill for producing a dated shop daily report with specific business, traffic, user-analysis, anomaly alerting, and recommendation outputs. This file instead accepts caller-supplied query specs and API paths, then executes concurrent raw data queries across shops, returning fetched results directly without any report-generation, date handling, anomaly detection, or business advice logic.

Static analysis

No suspicious patterns detected.