Back to skill

Security audit

抖音-蓝海爆品采集师 | 青虎AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin product-research workflow that uses Qinghu APIs and may create local exports, with no evidence of hidden execution or malicious behavior.

Before installing, be comfortable providing or exposing a Qinghu API token, approving potentially paid API calls, and having larger research results exported to local files by default. Avoid using it for unrelated product research unless you explicitly want the Douyin/Qinghu/1688 workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad enough to activate on common e-commerce and sourcing concepts such as keywords, hot searches, product selection, and suppliers, which increases the chance of unintended invocation. Because the skill can solicit API keys, call external paid tools, and export data by default, over-triggering can lead to unnecessary data handling, surprise charges, or routing user queries into a capability they did not clearly request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The listed trigger examples are ambiguous and lack scope constraints, so normal conversation about 'blue ocean products,' 'hot searches,' or 'finding suppliers' could invoke the skill even when the user did not intend to use this external-data workflow. In this skill's context, that is more dangerous because invocation can cascade into credential requests, external API calls, local exports, and paid point consumption.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs automatic export of datasets with 10 or more records and references cached local file paths, but does not require a user-facing notice or consent for local file creation and retention. This creates a data-handling risk: user-requested research results may be written to local storage unexpectedly, potentially exposing commercial research, links, or other collected data to later processes or users on the same system.

Static analysis

No suspicious patterns detected.