Back to skill

Security audit

Pinduoduo Listing

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it generates misleading marketplace claims and incentivized review requests, and one helper logs user inputs locally without clear notice.

Before installing, treat generated copy only as drafts. Do not publish sales numbers, review rates, scarcity statements, guarantees, or testimonials unless you can verify them, and avoid using the review-incentive templates unless current marketplace rules and law clearly allow them. Be aware that the pinduoduo-listing helper can store command inputs in a local history file.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

other

Warning
Location
scripts/pdd.sh:122
Finding
Generation of Unsupported Commercial Claims and Fabricated Social Proof<![CDATA[ ## Vulnerability Details **File Location**: `scripts/pdd.sh:122-131` **Additional Locations**: `scripts/pdd.sh:51, 91, 109, 112, 176-177, 296, 303` **Vulnerability Type**: Deceptive commercial content generation **Risk Level**: Medium ### Complete Code Snippet ```python pdd_prefixes = ["【百亿补贴】", "【限时秒杀】", "【工厂直发】", "【全网最低】", "【今日特价】", "【拼团价】"] { "style": "口碑型", "text": ( "📢 {product} | 10万+买家的共同选择!\n\n" "💬 买家真实评价:\n" " 「这个价格能买到这个品质,真的绝了」\n" " 「已经是第三次回购了,品质稳定」\n" " 「推荐给朋友,都说物超所值」\n" " 「比实体店便宜太多了,品质一样」\n\n" "📊 数据说话:\n" " · 累计销量 100000+\n" " · 好评率 98.6%\n" " · 复购率 45%\n\n" "🤝 我们的底气:\n" " 源头厂家 → 没有中间商 → 价格最实惠\n" " 严格品控 → 出厂必检 → 品质有保障\n\n" " 这就是为什么大家都选我们的{product}!" ).format(product=product), } ``` Related hard-coded scarcity and participation claims include: ```python "⏰ 仅剩最后50个名额!\n" "👥 已有2846人参与拼团\n\n" ``` ### Technical Analysis The generator emits factual-looking claims without accepting or validating evidence for them. These claims include precise sales totals, favorable-review rates, repeat-purchase rates, current participant counts, remaining availability, marketplace subsidy eligibility, lowest-price status, manufacturing equivalence, and product guarantees. Because these values are hard-coded, the same assertions can be generated for any arbitrary product. The output does not label the figures as examples or placeholders and does not require the merchant to confirm them before use. Consequently, ordinary use of the tool can produce unsupported advertising and fabricated social proof. This issue does not provide operating-system privileges or code-execution capabilities. It affects the integrity and compliance of commercial content generated by the skill. ### Attack Path 1. A user invokes a command such as `pdd.sh desc "Product"` or `pdd.sh group "Product" "29.9"`. 2. The script inserts hard-coded ...[truncated 1013 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Replace every hard-coded factual claim with an explicit placeholder, such as `[VERIFIED SALES COUNT]`, `[ACTUAL REVIEW RATE]`, or `[CONFIRMED INVENTORY]`. 2. Require merchants to supply factual values through command arguments or a validated input file. 3. Clearly mark all generated examples as drafts that must not be published without verification. 4. Add validation rules for: - Sales and participation counts. - Review and repeat-purchase rates. - Remaining inventory and time-limited offers. - Lowest-price or subsidy-program claims. - Manufacturing-equivalence and authenticity claims. - Refund, replacement, and compensation guarantees. 5. Reject generation of regulated or comparative claims unless the user confirms that supporting evidence is available. 6. Record the source and verification date for every factual claim used in generated copy. 7. Add compliance-oriented templates that describe product features without inventing metrics, testimonials, urgency, or guarantees. ]]>

other

Warning
Location
scripts/pdd.sh:490
Finding
Financial Incentives for Reviews and Follow-Up Reviews<![CDATA[ ## Vulnerability Details **File Location**: `scripts/pdd.sh:490-502` **Additional Location**: `tips.md:91` **Vulnerability Type**: Review manipulation guidance **Risk Level**: Medium ### Complete Code Snippet ```python templates = [ "亲,您好!您购买的宝贝用了有一段时间了,使用感受还满意吗?如果方便的话,希望您能追评分享一下使用体验,帮助更多买家做参考。追评后联系客服领取5元无门槛优惠券哦~ 感谢支持!❤️", "Hi亲~ 还记得前几天买的宝贝吗?用得怎么样呀?如果觉得不错,麻烦花1分钟追评一下,写上真实感受就好。追评晒图还能领取精美小礼品,感谢您!😊", "亲爱的,您的使用体验对其他买家很重要!如果宝贝用着满意,希望您能追评告诉大家。我们为追评用户准备了专属福利:① 5元返现 ② 下次购买9折 ③ 新品试用资格。任选其一!🎁", ] print(" 📌 追评激励方式:") print(" · 追评返现(2-5元红包)") print(" · 追评送券(下次购买可用)") print(" · 晒图追评额外奖励") print(" · 视频追评最高奖励") ``` The accompanying operational guidance also states: ```markdown - 包裹里放好评卡(返现2-3元,避免违规) ``` ### Technical Analysis The project recommends cash, coupons, gifts, discounts, and other benefits in exchange for reviews or follow-up reviews. Some templates condition the incentive on satisfaction or encourage positive follow-up content, which can bias customer feedback rather than solicit neutral reviews. The guidance in `tips.md` also recommends a cashback card for favorable reviews while referring to avoiding policy violations. This can facilitate attempts to manipulate marketplace reputation and evade review-integrity controls. This issue does not compromise the host system or grant additional technical privileges. It undermines the integrity of marketplace review systems and may cause users to violate platform or consumer-protection requirements. ### Attack Path 1. A merchant invokes `pdd.sh review-reply "followup"` or reads the review guidance in `tips.md`. 2. The tool generates messages offering cash, coupons, discounts, gifts, or other rewards for a follow-up review. 3. The merchant sends the generated message to customers or includes a cashback card in product packaging. 4. Customers are financially encouraged to submit favorable, illustrated, or video reviews. 5. The incentivized reviews alter the apparent reputatio ...[truncated 535 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove all cash-for-review, coupon-for-review, gift-for-review, and discount-for-review templates. 2. Do not condition feedback requests on whether the customer is satisfied. 3. Replace the affected templates with neutral language requesting honest feedback regardless of sentiment. 4. Do not offer greater rewards for photographs, videos, favorable ratings, or follow-up reviews. 5. Where incentives are legally and contractually permitted, ensure that: - The incentive is not dependent on review sentiment. - The review clearly discloses the incentive. - The relevant marketplace expressly permits the practice. 6. Remove language suggesting that users can avoid or conceal policy violations. 7. Add a compliance warning advising merchants to review current marketplace review-integrity rules before contacting customers. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This shell/Python script presents its help text, prompts, and generated output entirely in Chinese, and its stated purpose is specific to 拼多多 content generation. The file does not offer user opt-in, language selection, or explain a justified locale restriction, which fits the language/locale policy-violation category.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
User-provided content is written persistently to a local history file without any user-facing notice or consent. If users enter sensitive draft text, campaign plans, proprietary ideas, or accidental secrets in arguments, those values remain on disk and may be exposed to other local users, backups, or forensic review.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The natural-language description repeatedly presents the skill content in both Chinese and English, but does not state whether output will follow the user's preferred language or allow opt-in to a specific locale. Under the language/locale policy, forcing or assuming a language without user choice can be a policy concern.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The file-level comment and help text present the tool as a content-generation assistant, while the implementation additionally creates a data directory and records command arguments to a history log. That persistence behavior is not just omitted detail in one function; it is a cross-cutting behavior that affects all commands and changes the tool's effective intent.

Natural-Language Policy Violations

Low
Confidence
61% confidence
Finding
The script is explicitly branded for 'pinduoduo', which suggests a locale-specific usage context, but there is no natural-language indication that users can choose another language or locale. If organizational policy requires avoiding forced locale assumptions without opt-in, this wording can be read as imposing a specific locale context.

Intent-Code Divergence

Low
Confidence
91% confidence
Finding
The file is primarily informational content, but the closing line introduces an undocumented command interface (`pdd.sh help`). In an agent/skill context, this can mislead users or downstream systems into trusting and invoking a command surface that is not described or validated here, creating confusion and potential unsafe command execution if such a script exists elsewhere.

Static analysis

No suspicious patterns detected.