Back to skill

Security audit

query-1688-product-detail

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles long-lived API credentials and uses overly forceful instructions that could push users or agents into unsafe credential sharing and unnecessary third-party API use.

Install only if you are comfortable sending 1688 product IDs to AlphaShop and storing AlphaShop API credentials for this skill. Configure secrets through a protected config or secret mechanism, do not paste apiKey or secretKey into chat, restrict and monitor the AlphaShop account, and prefer pinned dependencies before production use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:4
Finding

Overly Broad Mandatory Skill Routing and Alternative-Method Suppression

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4 and SKILL.md:11-17
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable excerpt:

yaml
description: Query 1688 cross-border product details via AlphaShop API using productId extracted from URL or provided directly. **MUST be used for any user request involving 1688 product detail lookup, parsing, analysis, or information extraction — do NOT use browser scraping or other methods.**
markdown
**ALWAYS use this skill when the user requests anything related to 1688 product information, including but not limited to:**
- "Get 1688 product details"
- "Query product details"
- "Parse a product"
- "Analyze this 1688 link"
- "Extract product information"
- "View product specifications"
- Any similar intent involving 1688 product data extraction

Technical Analysis

The Skill instructs the hosting agent that it must select this Skill for a broad range of 1688-related requests and explicitly prohibits alternative methods. These directives go beyond documenting the Skill's capabilities: they attempt to control tool routing and constrain the agent's available approaches whenever the Skill is loaded.

This can redirect requests that could otherwise be handled locally or through a user-selected method to the third-party AlphaShop API. The broad phrase “anything related to 1688 product information” also risks capturing tasks that do not require an authenticated product-detail API.

Attack Path

  1. The Skill metadata and instructions are loaded into the agent's context.
  2. A user submits a request involving analysis, parsing, or extraction of 1688 product information.
  3. The agent follows the mandatory MUST and ALWAYS directives instead of independently selecting the least-privileged method.
  4. The agent invokes query.py, which creates an authenticated AlphaShop token and sends the product identifier ...[truncated 521 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace mandatory routing language such as MUST, ALWAYS, and “do not use other methods” with neutral capability and eligibility guidance.
  • Limit activation guidance to explicit product-detail API requests for which AlphaShop is an appropriate source.
  • Preserve user choice when the user requests a specific data source or processing method.
  • State clearly that external API use requires user authorization and transmits the product identifier to AlphaShop.
  • Ensure Skill instructions cannot override system policies, safety controls, or higher-priority user requirements.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:27
Finding

Instructions Encourage Users to Disclose API Credentials in Conversation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-37
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable excerpt, translated into English from the documentation:

markdown
Before using this Skill, the following keys must be configured:

| Configuration | Description | Required |
| `apiKey` | AlphaShop API Access Key | Yes |
| `secretKey` | AlphaShop API Secret Key | Yes |

If the user has not provided these keys, you must first ask the user to obtain them before continuing.

The executable subsequently consumes the corresponding credentials:

python
def get_api_key():
    """Generate JWT token using ALPHASHOP_ACCESS_KEY and ALPHASHOP_SECRET_KEY."""
    ak = os.environ.get("ALPHASHOP_ACCESS_KEY", "").strip()
    sk = os.environ.get("ALPHASHOP_SECRET_KEY", "").strip()

Technical Analysis

The documentation directs the agent to ask the user for an API access key and secret key when they are unavailable. If interpreted as requesting the credential values in chat, this places reusable secrets into conversation history rather than a protected secret-management channel.

Conversation content may be retained in logs, telemetry, support exports, agent context, or other storage systems with a broader access scope than the intended OpenClaw secret configuration. The Secret Key is particularly sensitive because query.py uses it as the HMAC key for generating HS256 bearer tokens.

The implementation itself reads credentials from environment variables and does not print their values. The vulnerability arises from the conversational credential-acquisition instruction and the inconsistency between asking the user for credentials and the documented secure configuration mechanism.

Attack Path

  1. The Skill is invoked without configured AlphaShop credentials.
  2. The agent follows the instruction to ask the user for the missing Access Key and Secret Key ...[truncated 954 chars]
Remediation
View remediation

Remediation Suggestions

  • Never instruct the agent to request or accept secret values through conversational messages.
  • Direct users to configure credentials exclusively through OpenClaw's protected secret or configuration interface.
  • Distinguish between confirming that credentials are configured and requesting the credential values themselves.
  • Redact credential-shaped values if users accidentally include them in chat.
  • Revoke and rotate any credentials previously disclosed through conversations.
  • Document the exact secure mapping from apiKey and secretKey configuration fields to ALPHASHOP_ACCESS_KEY and ALPHASHOP_SECRET_KEY.
  • Apply API-side restrictions, usage limits, monitoring, and rapid revocation procedures to reduce the impact of accidental exposure.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Versions

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable excerpt:

text
requests>=2.25.0
PyJWT>=2.0.0

Technical Analysis

Both dependencies use open-ended minimum-version constraints. Each installation may therefore resolve to any later release available from the configured package index. This prevents deterministic builds and allows future, unaudited dependency changes to enter the Skill environment without a corresponding project update.

requests handles the authenticated outbound HTTPS request, while PyJWT processes the AlphaShop Secret Key and creates the bearer token. A compromised or unexpectedly incompatible release of either package would execute in the Skill's process and have access to its input, environment variables, and network privileges.

No typosquatted package name, nonstandard package index, or presently malicious dependency was identified in the reviewed files. The confirmed weakness is the absence of upper bounds, exact pins, hashes, or a lock file.

Attack Path

  1. An operator installs the project dependencies at a later time.
  2. The package resolver selects newer releases permitted by the >= constraints.
  3. A selected release contains a supply-chain compromise, malicious installation behavior, or a security-relevant incompatible change.
  4. The dependency executes during installation or when imported by query.py.
  5. Malicious dependency code can access the process environment, including AlphaShop credentials, and can use the process's network and file permissions.

This path depends on a compromised or unsafe future dependency release; the audit did not establish that currently available releases are malicious.

Impact Assessment

The maximum practical scope is the privilege level of the user or service installing and running the Skill. A compromised dependency c ...[truncated 265 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each dependency to a reviewed exact version instead of using an unbounded minimum version.
  • Generate a lock or constraints file containing resolved transitive dependency versions.
  • Require cryptographic package hashes during installation, such as through pip install --require-hashes.
  • Install only from a trusted, explicitly configured package index.
  • Use automated vulnerability and dependency-integrity scanning in continuous integration.
  • Review and deliberately update pins on a controlled schedule rather than accepting new releases automatically.
  • Run installation and execution in a least-privileged isolated environment with only the required credentials and network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to place long-lived API credentials directly into persistent configuration but provides no guidance on secret handling, least privilege, rotation, or avoiding logging/version control exposure. In an agent skill ecosystem, this increases the chance that sensitive AlphaShop credentials are stored insecurely and later leaked through config sync, screenshots, support bundles, or repository commits.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires network access to an external API and handles authentication secrets, but it declares no explicit tool scope or permissions boundary. This increases the chance of unintended capability exposure and makes it harder for the agent runtime or reviewer to constrain what the skill may access or transmit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger language is excessively broad, using terms like 'ALWAYS use this skill' for anything related to 1688 product information. This can cause the agent to invoke the skill for loosely related requests, unnecessarily sending user-supplied URLs or IDs and increasing external data exposure or workflow hijacking risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill transmits product identifiers and authentication material to a third-party external endpoint. External transmission is expected for this skill's purpose, but it still introduces confidentiality, integrity, and dependency risk if users are not clearly informed or if the destination is not tightly constrained.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## API details

- **Endpoint:** `POST https://api.alphashop.cn/alphashop.openclaw.offer.detail.query/1.0`
- **Auth:** `Authorization: Bearer <api_key>`
- **Body:** `{"productId": "<id>"}`

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · query.py (reported line 12)May include surrounding context.

python
import time
import jwt

API_URL = "https://api.alphashop.cn/alphashop.openclaw.offer.detail.query/1.0"

def get_api_key():
    """Generate JWT token using ALPHASHOP_ACCESS_KEY and ALPHASHOP_SECRET_KEY."""

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and usage text describe querying product details using a productId extracted from a URL or provided directly. However, the parser explicitly extracts an 'offerId' from URL path/query patterns and main() sends that value as the API field 'productId', so the inline documentation and actual identifier semantics contradict each other.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · query.py (reported line 109)May include surrounding context.

python
for pid in product_ids:
        payload = {"productId": pid}
        try:
            resp = requests.post(API_URL, json=payload, headers=headers, timeout=15)
            if resp.status_code == 200:
                data = resp.json()
                data["input"] = pid

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions, headings, and usage notes are all presented in Chinese, which effectively forces a single language for users reading the skill documentation. There is no opt-in language selection or statement that the skill is intentionally limited to Chinese-speaking or region-specific users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The visible label and authoring context are entirely Chinese, and the document provides no indication that users may choose another language for interaction or output. Under the policy, locale or language constraints should be optional, user-chosen, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## When to use

**ALWAYS use this skill when the user requests anything related to 1688 product information, including but not limited to:**
- "获取1688商品详情"
- "查商品详情" 
- "解析商品"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency specifier requests>=2.25.0 is unpinned, so installations may resolve to different versions over time and across environments. This weakens build reproducibility and makes it impossible to verify whether deployed versions include fixes for known security advisories affecting requests.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.25.0
PyJWT>=2.0.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin a version, there is no reliable way to determine whether the installed release is affected. In a skill that queries external APIs, use of a vulnerable HTTP client could expose credentials, weaken TLS/request validation behavior, or otherwise increase attack surface depending on the resolved version.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency specifier PyJWT>=2.0.0 is unpinned, allowing different versions to be installed unpredictably. For a package involved in token parsing/validation, this increases security risk because vulnerable or behavior-changing releases could be introduced without review.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.25.0
PyJWT>=2.0.0

Unverifiable Dependency: PyJWT has 16 known advisory(ies) (CVE-2026-32597 (PyJWT accepts unknown `crit` header extensions); CVE-2024-53861 (PyJWT Issuer field partial matches allowed); CVE-2026-48522 (PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token ) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

PyJWT has multiple known advisories, and the unpinned dependency prevents verification that the installed version is safe. Because this skill likely interfaces with an API and includes JWT tooling, a vulnerable JWT library could affect token validation, issuer handling, or key retrieval behavior, making the context somewhat more security-sensitive than a generic utility dependency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.