Back to skill

Security audit

Taobao Price Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Taobao price lookup tool, but it overstates its monitoring features and asks users to provide a sensitive Taobao cookie without adequate safeguards.

Review before installing. Use only a low-risk, dedicated Taobao session if a cookie is necessary, treat TAOBAO_COOKIE like a password, and avoid exposing any local API or exported price data beyond your machine. Expect the current artifact to provide basic price lookup rather than the full monitoring, alerting, history, and comparison system described.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Dependencies Allow Unreviewed Supply-Chain Changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14-18 and SKILL.md:27-31
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

json
{
  "id": "requests",
  "kind": "pip",
  "package": "requests",
  "label": "安装依赖:pip3 install requests",
},
bash
pip3 install requests playwright
playwright install

Technical Analysis

The installation instructions request requests and playwright without exact version constraints, package hashes, or a lockfile. Consequently, each installation can resolve to dependency versions that differ from those reviewed during this audit. The playwright install command also downloads browser artifacts whose versions depend on the dynamically resolved Playwright release.

The skill metadata declares only requests, while the quick-start instructions additionally install Playwright and its browser payload. This discrepancy makes the complete dependency set less visible to automated installation and review processes.

No malicious dependency is currently identified in the reviewed files. The confirmed weakness is the absence of reproducible, integrity-verified dependency resolution. Exploitation requires compromise of an upstream package release, package-distribution account, dependency artifact, or another relevant part of the package supply chain.

Attack Path

  1. An attacker compromises a dependency release or its distribution channel, or publishes a malicious version that is selected by dependency resolution.
  2. A user follows the documented installation instructions:
    bash
    pip3 install requests playwright
    playwright install
    
  3. Because no versions or hashes are specified, the installer resolves and downloads the affected release or artifact.
  4. Malicious installation logic or imported runtime code executes under the account running the installation or skill.
  5. The payload can ac ...[truncated 672 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version, for example:
    text
    requests==<reviewed-version>
    playwright==<reviewed-version>
    
  2. Generate a lockfile or fully pinned requirements file that includes transitive dependencies.
  3. Require cryptographic hashes during installation, such as with pip install --require-hashes -r requirements.txt.
  4. Declare Playwright consistently in both skill metadata and installation documentation so automated review covers the complete dependency set.
  5. Pin and verify Playwright browser artifacts rather than implicitly downloading artifacts selected by an unconstrained package release.
  6. Install dependencies in an isolated virtual environment as a non-privileged user.
  7. Use a trusted package index, monitor dependency advisories, and review updates before changing pinned versions.
  8. Add automated dependency and lockfile integrity checks to the release process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明强调“监控”商品价格,并支持“历史价格查询、降价提醒、比价功能”,适合持续跟踪价格变化的场景。但提供的代码只是一次性查询当前商品信息的工具:它没有数据库/文件持久化来保存历史价格,没有定时任务、通知、告警机制,也没有对多个商品或多个来源进行价格比较的实现。代码的实际核心能力是当前价格抓取,而不是完整的价格监控与提醒系统。因此描述对功能范围有明显夸大,属于描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents clear network-dependent behavior (curl, scraping Taobao/Tmall, API access) but does not declare any tool scope such as permissions or allowed-tools. Missing capability declarations weaken least-privilege controls and make it harder for users or the platform to understand and restrict what the skill may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to store a Taobao cookie in configuration to bypass anti-scraping, but does not clearly warn that the cookie is sensitive authentication material that may grant account access and may be transmitted on requests. Mishandling this secret could expose the user's session, shopping/account data, or enable account abuse if logs, configs, or downstream tooling leak it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

技能支持 HTTP API 调用,适合集成到其他系统:

bash
curl http://localhost:18789/skills/taobao-price-monitor/query \
  -d '{"item_id": "123456789"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function accepts an arbitrary Cookie value and forwards it to a third-party Taobao endpoint, which can disclose session credentials or other sensitive tokens if a user provides real browser cookies. In a price-monitoring skill, this is more dangerous because the comment explicitly suggests using cookies to bypass anti-scraping, increasing the likelihood that operators will paste authenticated cookies without understanding the exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation exposes local HTTP API usage and data export capabilities without warning about access control, local service exposure, or leakage of monitored product datasets. While the example targets localhost, absent guidance may lead users to bind services insecurely, expose them via port forwarding, or export sensitive business monitoring data without safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s natural-language description and user-facing usage text are exclusively in Chinese, with no indication that language selection is optional or region-specific by design. Under the stated policy, forcing a specific language without opt-in can be considered a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.