Back to skill

Security audit

Jd Price History

Security checks for vulnerabilities and agentic risk

Overview

This skill is a shopping price-history helper with disclosed, purpose-aligned behavior and no hidden execution logic in the artifact.

Before installing, treat the skill as a JD shopping assistant: provide explicit product URLs or SKUs, confirm any price alert or monitoring setup, and prefer an isolated environment because the requests dependency is not pinned.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Python Dependency Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-19
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable configuration:

yaml
"install":
  [
    {
      "id": "requests",
      "kind": "pip",
      "package": "requests",
      "label": "安装依赖:pip3 install requests",
    },
  ]

Technical Analysis

The skill installs the third-party Python package requests without specifying an exact version or cryptographic hash. Consequently, pip resolves whichever compatible release is available from the configured package index at installation time. This makes installations non-reproducible and prevents verification that the installed artifact is the version reviewed by the skill author.

The dependency name is a legitimate public package, and the audited file contains no evidence that it is currently compromised. However, if the package index, publisher account, dependency resolution path, or local pip configuration were compromised, an attacker-controlled package artifact could be selected. A malicious source distribution or build backend may execute code during package installation.

Attack Path

  1. An attacker compromises the upstream package publication process, configured pip index, package publisher account, or dependency resolution environment.
  2. The attacker publishes or serves an altered release under the expected requests package name.
  3. A user installs the skill, causing pip to resolve the unpinned package from the active index.
  4. Pip downloads and processes the attacker-controlled artifact.
  5. Malicious build or installation code executes with the privileges of the user or service performing the installation.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installer account. Depending on that account's privileges, the attacker could access files and credentials available to the account, modi ...[truncated 275 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin requests to a reviewed exact version rather than allowing unconstrained resolution.
  • Record cryptographic hashes for every permitted distribution and install with pip --require-hashes.
  • Maintain dependencies in a version-controlled lock file generated from an audited dependency set.
  • Use only a trusted package index and explicitly configure the approved index URL.
  • Disable unnecessary supplemental indexes to reduce dependency-confusion exposure.
  • Perform dependency vulnerability and provenance checks before updating the pinned version.
  • Install dependencies in an isolated virtual environment or container under a non-privileged account.
  • Prefer prebuilt, verified wheels and restrict source builds where operationally feasible.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation examples are broad, natural-language prompts without clear trigger boundaries or parameter constraints. This can cause the agent to activate on ambiguous shopping-related requests and perform unintended actions such as monitoring, notifications, or recommendations based on loosely matched user input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.