Back to skill

Security audit

inquiry-1688

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its stated 1688 inquiry workflow, but it can automatically send inquiry results to a fixed DingTalk recipient and uses unsafe scheduled-agent instructions.

Review this skill before installing. Only use it if the DingTalk target 238382 is definitely the intended recipient for all inquiry results, and prefer a version that confirms submissions, stores the requester identity with each task, routes replies dynamically, escapes user input safely, and pins dependencies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:132
Finding

Inquiry Results Are Sent to a Hardcoded DingTalk Recipient

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:111
Finding

Untrusted Inquiry Values Are Interpolated into Shell and Scheduled-Agent Instructions

Content
View full analysis
","productId":"<商品ID>","url":"<商品链接>","question":"<用户问题>","submitTime":""}' >> "$TRACK_FILE" ``` The scheduled-agent payload also embeds task and user-controlled values directly into executable instructions: ```text "message": "你是询盘结果查询助手。请严格执行以下步骤:\n\n1. 执行查询命令:\npython3 /home/admin/.openclaw/workspace/skills/inquiry-1688/scripts/inquiry.py query \"{taskId}\"\n\n2. 将结果总结为中文消息,包含:\n 📋 询盘结果\n 商品链接: {链接}\n 用户原始问题: {用户的问题}\n 商品名称 + 价格 + 供应商名称\n 各问题的回答\n AI 总结\n\n3. 使用 message 工具发送到钉钉:\n message action=send channel=dingtalk target=238382 message=\"整理好的询盘结果\"\n\n4. 清除追踪记录:\npython3 /home/admin/.openclaw/workspace/skills/inquiry-1688/scripts/inquiry.py remove-pending \"{taskId}\"\n\n⚠️ 必须用 message 工具发钉钉!不要用 sessions_send,不要写文件!" ``` ### Technical Analysis The skill directs an agent to substitute task identifiers, product URLs, and user questions directly into shell text, JSON text, and a free-form `agentTurn` prompt. No escaping, structured serialization, or strict validation is specified. In the shell example, a value containing a single quote, newline, shell operator, redirection, or command substitution can terminate the intended quoted JSON and alter the command. Constructing JSON using `echo` is also unsafe because quotes and line breaks in user input can corrupt the JSON Lines tracking file. The scheduled-agent instruction creates a second injection boundary. An attacker can place instruction-like content in a product URL or inquiry question. Once interpolated into the `agentTurn` message, that content becomes part of the instructions interpreted by a privileged isolated agent with command and messagin ...[truncated 1901 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Third-Party Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=2.20.0 PyJWT>=2.0.0 ``` ### Technical Analysis The dependency file specifies only minimum versions and provides no upper bounds, exact versions, lock file, or integrity hashes. Consequently, separate installations can resolve to different package releases, including releases published after the skill was audited. This does not establish that either named package is malicious. The risk is that the reviewed artifact does not define a reproducible dependency set. Any future, compromised, or incompatible release satisfying the broad version constraints can be installed automatically and will execute in a process that has access to AlphaShop credentials and inquiry data. ### Attack Path 1. An operator installs the skill dependencies at a later date. 2. The package resolver selects the newest releases satisfying the broad `>=` constraints. 3. The selected code differs from the versions used during development or security review. 4. A compromised, malicious, or unexpectedly incompatible dependency executes when `inquiry.py` imports or invokes it. 5. The dependency runs with access to the process environment, including AlphaShop access and secret keys, and can observe API requests and inquiry responses. ### Impact Assessment A compromised dependency could operate with the full privileges of the Python process. Potentially exposed assets include: - `ALPHASHOP_ACCESS_KEY` - `ALPHASHOP_SECRET_KEY` - Generated bearer tokens - Inquiry questions and addresses - Supplier responses - Files accessible to the skill process - Network access available to the runtime The finding represents supply-chain and reproducibility risk rather than proof that the currently named dependencies contain malicious code. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented purpose and the described behavior diverge materially: the skill claims a bounded inquiry workflow but also introduces local task tracking and proactive delivery behavior that are not cleanly reflected in the declared interface. This mismatch reduces transparency and can hide security-relevant behaviors such as persistent storage and unsolicited outbound messaging.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are extremely broad and overlap with normal conversation, increasing the chance that the skill activates unintentionally. Because the skill can submit external inquiries, persist task state, and schedule follow-up actions, accidental activation could cause unauthorized outbound communications or data disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cron instructions hard-code outbound delivery to DingTalk target 238382 regardless of who initiated the inquiry. This can leak supplier responses, product links, quantities, addresses, or business intent to an unrelated recipient, making it a direct confidentiality and misdelivery issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes automatic inquiry submission, result retrieval, and DingTalk push notifications, but does not clearly disclose that user-provided questions, product links/IDs, task IDs, and reply data are transmitted to external platforms. In this context, missing disclosure increases privacy and compliance risk because users may unknowingly send business-sensitive procurement details to AlphaShop/1688 and DingTalk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example invocation phrases are broad, natural-language expressions such as asking a seller or supplier a question, which can overlap with ordinary conversation and cause the skill to trigger when the user did not intend to submit an external inquiry. In this skill's context, unintended activation is more dangerous because it can send product questions and identifiers to third-party services and create supplier-facing actions automatically.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares significant capabilities—environment variable access, file read/write, and network use—but does not restrict them with an explicit tool scope. In practice this weakens least-privilege boundaries and makes it easier for the skill to access secrets, persist data, and perform outbound actions beyond what a reviewer or user would expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L060 describes the core mechanism as cron querying results, writing them to a file, and the agent replying when the user next sends a message. Subsequent sections redefine the primary mechanism as proactive DingTalk push, with file-writing only as fallback, so the documentation presents two conflicting accounts of the intended main behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill shifts from a passive 'reply on next message' model to proactive external delivery via DingTalk, which expands the data flow and trust boundary. That creates a privacy and abuse risk because inquiry contents and supplier responses may be sent outside the original interaction context without clear per-user routing or consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cron payload instruction says '不要写文件' ('do not write files'), presenting file output as forbidden behavior for the task. Later, the fallback mechanism explicitly states that on DingTalk push failure the task will write results/{taskId}.md, which directly contradicts the earlier instruction rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cron payload explicitly instructs the agent to summarize results as a Chinese message (“将结果总结为中文消息”), and the document consistently assumes Chinese output without offering any language choice. This is a natural-language policy issue because it imposes a specific language on the user experience without opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/inquiry.py (reported line 49)May include surrounding context.

python
"Authorization": "Bearer {}".format(get_token())
    }
    try:
        r = requests.post(url, json=body, headers=headers, timeout=120)
        r.raise_for_status()
        return r.json()
    except requests.exceptions.HTTPError as e:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes submitting 1688 inquiries, waiting up to 20 minutes, fetching supplier replies, and pushing results via DingTalk. This file also implements separate local persistence-management capabilities for a pending_inquiries.json tracking file, including listing and removing entries, which are not described in the manifest and are not used as an obvious implementation detail within this script’s submit/query/poll flow.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency specification uses a lower-bound only version constraint for requests, which makes builds non-reproducible and can result in installing vulnerable or incompatible releases over time. In a skill that sends supplier inquiries and likely performs external HTTP requests, an unpinned HTTP client library increases the chance that a deployment unintentionally includes a version affected by known security issues.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.20.0
PyJWT>=2.0.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Requests has multiple known advisories, and because the manifest does not pin a version, there is no way to confirm that the deployed package is not affected. Given this skill’s business purpose of contacting external suppliers and likely fetching remote content or APIs, an outdated or vulnerable requests release could expose credentials, weaken TLS/request handling, or enable SSRF-style abuse depending on usage.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The PyJWT dependency is also unpinned, so the installed version may vary between environments and over time, making it impossible to verify whether known JWT-related vulnerabilities are present. If this skill uses JWTs for authentication, callbacks, or API integration, an unsafe version could weaken token validation and trust boundaries.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.20.0
PyJWT>=2.0.0

Unverifiable Dependency: PyJWT has 16 known advisory(ies) (CVE-2026-32597 (PyJWT accepts unknown `crit` header extensions); CVE-2024-53861 (PyJWT Issuer field partial matches allowed); CVE-2026-48522 (PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token ) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

PyJWT has known security advisories, and the lack of version pinning makes the risk unverifiable for this skill. If the skill relies on JWT parsing or validation for identity, webhook authentication, or service-to-service access, a vulnerable PyJWT version could permit improper token acceptance or related authentication bypass conditions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code rewrites pending_inquiries.json, which modifies user-local state, but the operation itself has no confirmation prompt and no inline comment or docstring warning near the write path explaining that the tracking file will be overwritten. Although the CLI help mentions removing a task, the file rewrite side effect is not explicitly disclosed at the point of the destructive file operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.