Back to skill

Security audit

1688 Sourcing Inquiry

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the stated 1688 procurement task, but it also handles and exposes sensitive AK/OAuth credential material in ways users should review carefully before installing.

Review this skill before installing. Use it only if you are comfortable giving it a 1688 AK, storing that credential locally, and having command usage reported to the 1688 gateway. Avoid running configure --status in shared logs or transcripts, and rotate the AK if it may already have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/callback_server.py:237
Finding

Reflected XSS in the OAuth callback can modify locally stored credentials

Content
View full analysis
0 else {} ak = body.get("ak", "") if not ak: self._send_json(400, {"success": False, "error": "MISSING_AK", "error_description": "AK 不能为空"}) return result = server_ref._save_ak(ak) server_ref._result = result if result.get("success"): server_ref._success = True self._send_json(200, result, cors_origin=origin or allowed) if result.get("success"): threading.Thread(target=lambda: server_ref._done_event.set(), daemon=True).start() ``` ### Technical Analysis The `error` and `error_description` query parameters are inserted directly into an HTML document without HTML escaping. This error-handling branch executes before OAuth ` ...[truncated 2011 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/capabilities/configure/service.py:27
Finding

AK credential is persisted as plaintext without explicitly enforced restrictive permissions

Content
View full analysis
bool: """将 AK 存储到 ak_store 文件""" try: AK_STORE_FILE.parent.mkdir(parents=True, exist_ok=True) with open(AK_STORE_FILE, "w", encoding="utf-8") as f: json.dump({"ak": ak}, f, ensure_ascii=False) return True except Exception: return False ``` The AK format is decoded into an access-key identifier and secret elsewhere in the project: ```python padded = raw_ak + "=" * (-len(raw_ak) % 4) decoded = base64.urlsafe_b64decode(padded).decode("utf-8") secret = decoded[:32] ak_id = decoded[32:] ``` ### Technical Analysis The AK is written directly into a JSON file. It is not an opaque public identifier: `_auth.py` establishes that the encoded value contains the AccessKeySecret in its first 32 decoded characters. The storage function does not explicitly create the parent directory with mode `0700` or the credential file with mode `0600`. On initial creation, effective permissions depend on the process umask. When overwriting an existing file, `open(..., "w")` preserves that file's existing mode, including an accidentally permissive mode. Base64URL encoding does not provide encryption or confidentiality. Any process that can read the file can recover the signing secret. ### Attack Path 1. A local user, same-host process, workspace collector, or backup process obtains read access to `.1688-AK/.ak_store.json`. 2. The attacker reads the plaintext `ak` property. 3. The attacker Base64URL-decodes the value or applies the implementation's fallback split. 4. The first 32 decoded characters provide the AccessKeySecret, and the remaining characters provide the AccessKey ID. 5. The attacker reproduces the HMAC signing algorithm from `_auth.py`. 6. The attacker sends sign ...[truncated 577 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/capabilities/configure/cmd.py:56
Finding

Configure status command discloses the complete secret-bearing AK

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/encrypted_store.py:21
Finding

OAuth fallback storage writes access and refresh tokens as plaintext JSON

Content
View full analysis
dict[str, str]: if not ENCRYPTED_TOKEN_FILE.exists(): return {} try: raw = ENCRYPTED_TOKEN_FILE.read_text(encoding="utf-8") return json.loads(raw) except (json.JSONDecodeError, Exception) as e: logger.warning("存储文件读取失败: %s,将重建", e) return {} def _save_store(data: dict[str, str]) -> None: json_bytes = json.dumps(data, ensure_ascii=False, indent=2).encode("utf-8") ENCRYPTED_TOKEN_FILE.parent.mkdir(parents=True, exist_ok=True) fd, tmp_path = tempfile.mkstemp( dir=str(ENCRYPTED_TOKEN_FILE.parent), prefix=".token_", suffix=".tmp", ) try: os.write(fd, json_bytes) os.close(fd) os.chmod(tmp_path, 0o600) os.replace(tmp_path, str(ENCRYPTED_TOKEN_FILE)) except Exception: try: os.close(fd) except OSError: pass if os.path.exists(tmp_path): os.unlink(tmp_path) raise def enc_store_token(key: str, value: str) -> None: store = _load_store() store[key] = value _save_store(store) logger.debug("Token 已写入文件存储: key=%s", key) def enc_load_token(key: str) -> str | None: store = _load_store() return store.get(key) or None ``` The fallback is selected when the OS keychain is unavailable: ```python def store_token(key: str, value: str) -> None: if is_keychain_available(): try: keyring.set_password(KEYCHAIN_SERVICE, key, value) logger.debug("Token 已写入 Keychain: key=%s", key) return except keyring.errors.KeyringError as e: error_msg = str(e) logger.error("Keychain 写入失败: %s" ...[truncated 2041 chars]
Remediation
View remediation

other

Note
Location
cli.py:391
Finding

Automatic usage telemetry is transmitted after every registered CLI command

Content
View full analysis
None: """ 上报 skill 调用次数到网关。 调用时机:每次 CLI 命令执行时调用一次(在 cli.py 的 main() 中触发)。 失败时静默处理,不抛出异常,不影响主流程。 """ try: from _http import api_post skill_name, skill_version, channel = _get_skill_env() api_post( "/api/reportSkillsUsage/1.0.0", { "apiName": None, "skillsName": skill_name, "version": skill_version, "scene": "CLI", "channel": channel, }, ) except Exception as exc: logger.debug("埋点上报失败(已忽略): %s", exc) ``` ### Technical Analysis After every registered command dispatch, the CLI attempts to transmit a usage record to the fixed 1688 Skill gateway. This includes commands whose primary purpose is local configuration or status handling. The reviewed payload does not contain procurement descriptions, OAuth tokens, or command arguments. However, it discloses invocation timing, Skill identity, version, execution scene, and channel. Because `api_post()` signs the request, the gateway also receives the AK identifier in the request headers. The telemetry is silently ignored on failure and is not prominently disclosed in the primary Skill behavior or security declaration. It also exceeds the minimum network access required for local-only commands. ### Attack Path 1. The user invokes any registered CLI capability. 2. The requested command completes or returns control to `main()`. 3. `main()` imports and calls `report_skill_usage()`. 4. The tracker sends invocation m ...[truncated 637 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (158)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Managing auth tokens, refreshing them through remote interfaces, revoking/clearing them, and checking OAuth scope is a substantial undeclared behavior set inconsistent with a simple RFQ publishing tool. In this skill context, that makes the mismatch more dangerous because users seeking supplier quotes may unknowingly invoke identity and authorization management actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents itself as a generic 1688 open-skill CLI with OAuth, token lifecycle, revocation, scope enumeration, and AK retrieval capabilities, which is far broader than the manifest's sourcing-inquiry purpose. This overbreadth increases the attack surface and enables privileged account operations unrelated to the declared user task, violating least privilege and making abuse harder to detect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

cmd_get_token emits a live access token to stdout in JSON, making credential material directly accessible to any caller, log pipeline, or chained tool. For a sourcing-inquiry skill, exposing bearer tokens is unnecessary and dangerous because anyone obtaining the token can perform authorized API actions until expiry, potentially beyond the user's intended workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file instructs the agent to collect and configure an Access Key for DingTalk message sending, which is unrelated to the declared 1688 sourcing/inquiry purpose. That scope mismatch is dangerous because it enables secret collection and external messaging capability under the cover of an unrelated procurement skill, increasing the chance of credential harvesting or unauthorized side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly asks the user for a credential and configures it through a local command despite no sourcing-related need for that secret. Unjustified secret collection is a serious design flaw because users may disclose sensitive credentials to a skill whose stated purpose gives no reason to expect credential handling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli.py (reported line 268)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli.py (reported line 272)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_const.py (reported line 74)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/token_manager.py (reported line 104)May include surrounding context.

python
TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/get_token_by_auth_code/1.0.0"
# 用 Refresh Token 换取新 Token 的网关端点
REFRESH_TOKEN_ENDPOINT = "https://skills-gateway.1688.com/api/refresh_token/1.0.0"
# Revoke 端点(吊销 Access Token / Refresh Token,通过 tokenTypeHint 区分)
REVOKE_ENDPOINT = "https://skills-gateway.1688.com/api/revoke_token/1.0.0"
# Scope 列表查询端点
SCOPE_LIST_ENDPOINT = "https://skills-gateway.1688.com/api/query_all_scope/1.0.0"

Credential Access

High
Category
Privilege Escalation
Confidence
75% confidence
Finding

The constants indicate that OAuth tokens may be stored in a local .env file under the workspace. Storing access and refresh tokens in plaintext configuration files increases the risk of credential disclosure through accidental commits, workspace sharing, backups, or other local file reads.

Content

Scanner excerpt · scripts/_const.py (reported line 91)May include surrounding context.

python
TOKEN_REFRESH_MARGIN = 60
SCOPE_CACHE_TTL = 86400

# ── .env 文件 ─────────────────────────────────────────────────────────────────
ENV_FILE = DATA_DIR / ".env"

# ── Scope 缓存文件 ────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
75% confidence
Finding

The adjacent constant for a scope cache file reinforces that sensitive auth-related state is being persisted under a workspace-controlled directory alongside a .env token file. While a scope cache alone is less sensitive, colocating auth metadata in a shared workspace can aid attackers in discovering and abusing stored credentials.

Content

Scanner excerpt · scripts/_const.py (reported line 92)May include surrounding context.

python
SCOPE_CACHE_TTL = 86400

# ── .env 文件 ─────────────────────────────────────────────────────────────────
ENV_FILE = DATA_DIR / ".env"

# ── Scope 缓存文件 ────────────────────────────────────────────────────────────
SCOPE_CACHE_FILE = DATA_DIR / ".scope_cache.json"

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/_const.py:98

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/callback_server.py:205

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/token_manager.py:53