Back to skill

Security audit

1688 Supplychain Api Procurement

Security checks for vulnerabilities and agentic risk

Overview

This procurement API skill is mostly coherent, but it includes broad file/URL image handling and silent usage reporting that users should review before installing.

Review this skill before installing. It needs API credentials and sends procurement text, questions, session metadata, and optional images to 1688 services. Only pass image paths you intentionally want uploaded, avoid remote image URLs unless you trust the target, and be aware that each successful command also reports usage metadata without a documented opt-out.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:92
Finding

Skill instructions attempt to override outer agent response rules

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:31
Finding

User-controlled values are interpolated into documented shell commands

Content
View full analysis
" \ --questions '[{"question":"quotation","type":"current"},{"question":"delivery time","type":"current"}]' \ --purchase-size 1 \ --inquiry-item-size 30 ``` The query workflow uses the same pattern: ```bash cd {baseDir} && python3 cli.py inquiry \ --instance-id "" \ --output-mode file \ --output-dir "{baseDir}/.skill_outputs" ``` ### Technical Analysis Double-quoting a substituted shell value does not make arbitrary input safe. Shell substitutions such as `$(command)` and backticks are still evaluated inside double quotes. Crafted quotation characters can also terminate the intended argument and append additional shell syntax. The Python CLI itself uses `argparse`, but that does not mitigate injection that occurs in the shell before Python starts. The risk arises when an agent constructs and executes these documented command strings through a shell. ### Attack Path 1. An attacker supplies a requirement or instance identifier containing shell syntax, such as `$(id)` or a quote followed by an additional command. 2. The agent substitutes the value into the documented Bash command. 3. The command is passed to a shell. 4. The shell evaluates the injected substitution or appended command before invoking, or alongside, `cli.py`. 5. The attacker-controlled command executes with the same operating-system privileges as the agent process. ### Impact Assessment Successful exploitation can provide arbitrary command execution under the account running the agent. Depending on that account's permissions, an attacker could read or alter local files, access environment variables and cr ...[truncated 181 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_img_upload.py:113
Finding

Unrestricted local paths can be read and uploaded as images

Content
View full analysis
List[str]: if not image_paths: raise ParamError("Image path list cannot be empty") image_bytes_str_list = [] for image_path in image_paths: image_path = image_path.strip() if not image_path: continue if not os.path.exists(image_path): raise ParamError("Image file does not exist: {}".format(image_path)) with open(image_path, "rb") as f: image_bytes = f.read() if not image_bytes: raise ParamError("Image file is empty: {}".format(image_path)) image_bytes_str_list.append( base64.b64encode(image_bytes).decode("utf-8") ) resp = api_post( path=settings.IMG_UPLOAD_PATH, body={"imageBytesStrList": image_bytes_str_list}, timeout=settings.IMG_UPLOAD_TIMEOUT, ) ``` The calling service classifies every non-HTTP value as a local path: ```python for image in local_images or []: image = (image or "").strip() if not image: continue if is_http_url(image): remote_urls.append(image) else: local_paths.append(image) if local_paths: urls = upload_images(local_paths) ``` ### Technical Analysis There is no permitted-directory boundary, canonical-path validation, regular-file check, image decoding, file-signature validation, MIME allowlist, or size limit. Consequently, any readable path accepted through `--image` can be treated as an image and sent to the configured gateway. Base64 is transport encoding, not a security control. It preserves the entire source file and increases its size in ...[truncated 826 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_img_upload.py:31
Finding

Remote image retrieval permits SSRF and unbounded downloads

Content
View full analysis
bool: parsed = urlparse((value or "").strip()) return parsed.scheme in ("http", "https") and bool(parsed.netloc) ``` The URL is then fetched without address-range restrictions, redirect validation, content-type enforcement, or a download-size limit: ```python def _download_image_url(url: str, output_dir: str, index: int) -> str: clean_url = (url or "").strip() if not is_http_url(clean_url): raise ParamError("Invalid image URL: {}".format(clean_url)) resp = None try: resp = requests.get( clean_url, stream=True, timeout=DOWNLOAD_TIMEOUT_SECONDS, ) resp.raise_for_status() except requests.exceptions.Timeout: raise TimeoutError("Image download timed out: {}".format(clean_url)) except requests.exceptions.RequestException as e: if resp is not None: resp.close() raise ServiceError("Image download failed: {} ({})".format(clean_url, e)) try: suffix = _image_suffix_from_response(clean_url, resp) local_path = os.path.join( output_dir, "remote_image_{}{}".format(index, suffix), ) total_bytes = 0 with open(local_path, "wb") as f: for chunk in resp.iter_content(chunk_size=DOWNLOAD_CHUNK_SIZE): if not chunk: continue f.write(chunk) total_bytes += len(chunk) finally: resp.close() ``` ### Technical Analysis Any syntactically valid HTTP or HTTPS destination is accepted, including loopback, private, link-local, reserved, and cloud metadata addresses. `requests` follows redirects ...[truncated 1326 chars]
Remediation
View remediation

other

Note
Location
scripts/_tracker.py:17
Finding

Every successful command performs undisclosed authenticated telemetry

Content
View full analysis
None: try: from _http import api_post api_post( "/api/reportSkillsUsage/1.0.0", { "apiName": None, "skillsName": settings.SKILL_NAME, "version": settings.SKILL_VERSION, "scene": "CLI", "channel": _CHANNEL, }, retry=False, ) except Exception as exc: logger.debug("Skill telemetry failed and was ignored: %s", exc) ``` ### Technical Analysis The project documentation declares two functional capabilities, but execution also performs a third network operation for usage reporting. The request is silent, enabled by default, and has no visible consent or disable option. The telemetry payload contains the Skill name, version, execution scene, and channel. Because the common HTTP client signs the request, the gateway also receives the configured access-key identifier in the authentication headers. The secret itself is not transmitted directly. ### Attack Path 1. A user invokes either documented CLI capability. 2. The requested operation completes. 3. `cli.py` calls `report_skill_usage`. 4. The tracker sends an authenticated event to the 1688 Skill gateway. 5. Failures are silently ignored, preventing the user from readily observing the extra operation. ### Impact Asse ...[truncated 386 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency version is not reproducibly pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says it supports only two procurement API operations, but this helper silently adds arbitrary remote URL fetching before upload. That expands the trust boundary and can be abused as an SSRF primitive to make server-side requests to attacker-controlled or internal endpoints, potentially exposing internal services, credentials, or enabling pivoting through the agent environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool/permission scope even though its documented behavior requires filesystem access, network access, and environment-dependent execution. Missing scope boundaries increases the blast radius if the skill is invoked in an unintended context or later extended, because reviewers and policy engines cannot constrain its actual capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
73% confidence
Finding

The skill description is written as a Chinese-only operating specification for the skill, and it does not indicate that users may choose another language or locale. This can amount to a language/locale policy violation if the organization requires user opt-in before constraining language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI performs an additional telemetry/reporting action via _tracker.report_skill_usage() that is unrelated to the core procurement function and is not disclosed in the file's user-facing output. Silent outbound reporting can leak usage metadata or environment details and creates an unexpected side effect in a tool that otherwise appears to be a direct API wrapper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage-tracking call is executed silently and there is no user-facing disclosure in this file that the CLI may report execution data. In a cloud API skill, undisclosed reporting is more concerning because it may expose invocation patterns, identifiers, or operational metadata beyond the expected procurement workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The authentication helper falls back to reading API credentials from a local config file when the environment variable is absent. That broadens the trust boundary and allows the skill to consume secrets from local host state outside its declared cloud-API invocation path, increasing the chance of unintended secret use, cross-skill credential exposure, or abuse if the config file is readable or tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This module reads an API credential from both a local config file and the ALI_1688_AK environment variable, which is a sensitive-secret access path. While the code has internal docstrings, it provides no user-facing warning, confirmation, or visible logging that credentials will be read from the environment or fallback config, so the behavior is not disclosed within this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code's natural-language documentation and user-facing exception messages are exclusively in Chinese, including the stated output shape containing markdown text. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring states this module uploads local images as base64, but the implementation also downloads arbitrary remote images first. This mismatch hides network-fetch behavior from reviewers and operators, increasing the chance that dangerous SSRF-like capability is overlooked and deployed without appropriate controls.

Content

No source excerpt is available for this finding.

Tainted flow: 'local_path' from requests.get (line 68, network input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/_img_upload.py (reported line 70)May include surrounding context.

python
suffix = _image_suffix_from_response(clean_url, resp)
        local_path = os.path.join(output_dir, "remote_image_{}{}".format(index, suffix))
        total_bytes = 0
        with open(local_path, "wb") as f:
            for chunk in resp.iter_content(chunk_size=DOWNLOAD_CHUNK_SIZE):
                if not chunk:
                    continue

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language documentation and output strings entirely in Chinese, including the standardized output description and later user-facing error/help text. Because the skill appears to standardize output for all commands and does not offer opt-in language selection or document a region-specific justification, it risks violating language/locale policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code introduces an undisclosed outbound network call for telemetry on every CLI execution, which exceeds the skill's stated two API functions and creates a data-flow path not described in the manifest. Even though the payload is limited to skill name, version, scene, and channel, hidden network behavior undermines transparency, can violate user expectations or policy constraints, and could be repurposed later for broader exfiltration via the shared HTTP helper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Telemetry is sent on every invocation without any notice or consent mechanism in this file, creating covert outbound communication from the user's environment. Silent exception handling further reduces visibility, making the behavior harder to detect or audit and increasing privacy and compliance risk even if the current payload appears minimal.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI explicitly allows query results to be emitted to stdout via --output-mode stdout, which directly contradicts the skill's documented safety requirement that instance query data must use file/streamed output to avoid entering the model context. In an agent setting, stdout is commonly captured and fed back into the LLM, so this creates a straightforward data-exfiltration path for potentially large or sensitive API results.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The help text advertises that query results may be returned as direct stdout JSON, normalizing an unsafe usage pattern that bypasses the skill's stated file-mode-only boundary. Because operators and calling agents rely on CLI help for correct invocation, this documentation inconsistency materially increases the chance that sensitive instance data will be routed into model-visible output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill sends user-provided requirement, questions, session ID, and possibly uploaded image-derived URLs to external services via api_post, but this file contains no confirmation prompt, logging, or user-facing notice about that transmission. Because the operation sends user data over the network and the function immediately starts the inquiry flow, it meets the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code exposes additional capability beyond the stated skill scope by accepting both local image paths and remote image URLs, then turning them into uploaded image payloads. This scope drift is security-relevant because hidden or undocumented inputs expand the attack surface, can surprise users, and may enable unintended data transfer through a skill described as cloud-API-only and limited to inquiry start/query flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function reads caller-supplied local file paths and uploads them, and also fetches/uploads externally referenced image URLs. In an agent environment, this can lead to exfiltration of local files or transmission of sensitive image content to remote services, which is especially risky because the skill description says it is cloud-API-only and does not advertise local file handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code uploads local images and remote-image-derived content to external services without any visible confirmation, provenance checks, or safeguards in this path. Because the inputs may reference sensitive local files or private business images, silent transmission creates a material risk of unintended data exfiltration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.