Back to skill

Security audit

电商价格比较

Security checks for vulnerabilities and agentic risk

Overview

This skill is a shopping price scraper, but it overstates what is implemented and includes guidance for evading anti-bot controls and installing risky unpinned packages.

Install only if you are comfortable with a JD-focused scraper whose documentation overclaims broader platform support. Use official or permitted APIs where possible, avoid proxy/IP-rotation or CAPTCHA-bypass workflows without authorization, and install dependencies in an isolated environment from pinned requirements rather than copying the README commands as written.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/README.md:27
Finding

Unpinned and Unnecessary PyPI Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: scripts/README.md, lines 27–28, 34, 37, and 40
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

The documented installation process uses mutable, unpinned PyPI dependencies and instructs users to install sqlite3 and asyncio, even though both names correspond to modules included in Python's standard library.

bash
pip install playwright beautifulsoup4 requests pandas numpy
playwright install chromium
bash
# Data visualization
pip install matplotlib seaborn

# Database storage
pip install sqlite3 pymongo

# Asynchronous processing
pip install aiohttp asyncio

Technical Analysis

None of the third-party dependencies are constrained to reviewed versions or verified with cryptographic hashes. Consequently, executing these commands installs whatever versions the configured package index resolves at that time. Future releases, compromised maintainer accounts, malicious dependency updates, or a compromised package index could therefore introduce code that was not part of the audited Skill.

The instructions to install sqlite3 and asyncio are particularly unsafe and unnecessary. These modules are supplied by supported Python versions and should not be retrieved from PyPI. A third-party distribution published under a standard-library module name is not required by this project and may contain unrelated or hostile code. This creates dependency-confusion and package-takeover exposure.

Several other documented dependencies are not used by the included scripts/jd_scraper.py, unnecessarily increasing the project's trusted computing base and supply-chain attack surface.

Attack Path

  1. A user or automated Agent follows the dependency installation instructions in scripts/README.md.
  2. pip queries its configured package index and resolves the unpinned package names to their currently available distributions ...[truncated 1246 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove sqlite3 and asyncio from all installation commands because they are Python standard-library modules.
  2. Remove packages that are not required by the files actually shipped with the Skill. The included scraper directly requires only reviewed dependencies corresponding to its imports, such as requests and beautifulsoup4.
  3. Define dependencies in a dedicated requirements or project metadata file rather than informal shell commands.
  4. Pin every direct and transitive dependency to an explicitly reviewed version using a generated lock file.
  5. Record and enforce cryptographic hashes, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  6. Separate optional dependencies into clearly identified extras so users do not install unrelated packages by default.
  7. Configure installations to use a trusted package index and consider an internally controlled dependency mirror for automated or production environments.
  8. Run dependency installation in an isolated virtual environment or container under a non-privileged account.
  9. Add automated dependency scanning and review dependency updates before regenerating the lock file.
  10. Document the supported Python version and verify that required standard-library modules are available without third-party installation.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码块的主功能是京东单平台商品信息抓取,文件名、类名、API端点和解析逻辑都明确指向 JD。虽然声明提到可从多个中国电商平台抓取并进行比较分析,但代码中没有任何淘宝、天猫、拼多多相关接口、适配器或比较逻辑。代码确实支持关键词搜索和商品链接解析,也能获取价格与部分促销信息,但缺失声明中的核心多平台比价、历史追踪和购买建议能力。因此描述明显夸大了实现范围,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and documents network-based scraping behavior across multiple e-commerce platforms, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and review gap: a host system or reviewer cannot clearly constrain or assess the skill's network access, increasing the risk of unexpected outbound requests, scraping abuse, or expansion of capabilities beyond what is explicitly approved.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report title and all surrounding report text are fixed in Chinese, which indicates the skill outputs content in a specific language by default. The file does not offer any user language selection or document that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation specifically advises frequent IP changes to deal with strict anti-crawling controls on Taobao, which is a direct evasion tactic. This materially increases the capability of the skill to circumvent platform restrictions rather than simply compare prices, making the skill more dangerous in context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section explicitly recommends anti-scraping evasion techniques such as random delays, proxy rotation, user-agent rotation, and captcha handling. In the context of a price-comparison skill, these instructions go beyond ordinary data collection and facilitate bypassing platform defenses, increasing the risk of unauthorized scraping and abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly discusses anti-bot handling, frequent IP rotation, browser automation, and login-state handling, but does not include clear legal, compliance, or account-risk warnings. In a scraping-focused skill targeting commercial e-commerce platforms, this omission can encourage users to perform actions that violate platform terms, trigger account bans, or cause proxy/IP abuse without understanding the consequences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request header forces Accept-Language to zh-CN,zh;q=0.9,en;q=0.8, which imposes a specific language/locale behavior. Under the policy, locale constraints should be user-selectable or clearly justified; this code does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file contains all user-facing instructions and examples in Chinese, but it does not state that the skill is Chinese-only or offer any language/locale choice. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. That creates a natural-language locale policy issue under the rule for language or locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file uses a single fixed language throughout and does not offer an alternative language or indicate that the locale is intentionally limited. Under the language/locale policy rule, forcing one language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.