Back to skill

Security audit

Taobao Merchant Ops

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Taobao automation package, but it needs review because it handles account session and license credentials in risky ways.

Install only if you trust the publisher and are comfortable giving this package access to a Taobao merchant browser session. Run it from a non-admin environment, keep the project folder private, do not share the generated license or storage-state JSON files, and prefer an HTTPS license server plus pinned dependency installation before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/license_gate.py:21
Finding

License Credentials and Machine Fingerprints Transmitted over Plaintext HTTP

Content
View full analysis
dict[str, Any]: body = json.dumps(payload).encode("utf-8") req = urllib.request.Request( url, data=body, headers={"Content-Type": "application/json"}, method="POST", ) try: with urllib.request.urlopen(req, timeout=timeout) as resp: text = resp.read().decode("utf-8") data = json.loads(text or "{}") return data if isinstance(data, dict) else {} ``` ```python def _remote_activate(card_key: str, machine_fp: str) -> dict[str, Any]: if not LICENSE_SERVER_URL: raise LicenseError("未配置授权服务器地址,请设置环境变量 TMO_LICENSE_SERVER。") url = f"{LICENSE_SERVER_URL}/api/activate" data = _http_post_json(url, {"card_key": card_key, "machine_fp": machine_fp}) if (data.get("status") or "").lower() != "ok": msg = str(data.get("message") or "卡密激活失败,请确认卡密是否正确或联系卖家。") raise LicenseError(msg) return data def _remote_check(machine_fp: str, card_key: str | None = None) -> dict[str, Any]: if not LICENSE_SERVER_URL: raise LicenseError("未配置授权服务器地址,请设置环境变量 TMO_LICENSE_SERVER。") url = f"{LICENSE_SERVER_URL}/api/check" payload: dict[str, Any] = {"machine_fp": machine_fp} if card_key: payload["card_key"] = card_key data = _http_post_json(url, payload) if (data.get("status") or "").lower() != "ok": msg = str(data ...[truncated 1774 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/license_gate.py:190
Finding

Reusable License Key and Authenticated Browser State Stored as Unprotected JSON

Content
View full analysis
None: path.parent.mkdir(parents=True, exist_ok=True) path.write_text(json.dumps(data, ensure_ascii=False, indent=2), encoding="utf-8") ``` The browser context is also persisted directly: ```python page.goto("https://sycm.taobao.com/mc/ci/shop/overview", timeout=30000) human_sleep(2, 3) record_step(step_results, 1, "打开生意参谋", True, extra=page_state(page)) wait_for_login(page, step_results) page.context.storage_state(path=CONFIG["storage_state_file"]) log("登录状态已保存") ``` The configured paths are inside the project tree: ```json "license_file": "license/license.json", "storage_state_file": "scripts/yingdao_storage_state.json", ``` ### Technical Analysis The activation file retains the complete reusable card key in plaintext. Playwright storage-state files commonly contain cookies and local-storage values used to restore an authenticated browser session. Both files are created as normal JSON files without explicit owner-only permissions, encryption, or integration with an operating-system credential store. Keeping browser state and licensing credentials beneath the source directory also increases the likelihood that they will be copied into archives, backups, support bundles, or source-control commits. No ignore file or cleanup control was present in the audite ...[truncated 1327 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/install.py:94
Finding

Mutable Remote Bootstrap and Unpinned Dependencies Permit Supply-Chain Code Execution

Content
View full analysis
None: """确保 pip 可用""" try: run([str(PY), "-m", "pip", "--version"], check=True) except SystemExit: print("[*] pip 不可用,尝试安装 pip...") try: run([str(PY), "ensurepip", "--upgrade"], check=True) except SystemExit: print("[*] ensurepip 失败,下载 get-pip.py...") run( [ str(PY), "-c", "import urllib.request; urllib.request.urlretrieve('https://bootstrap.pypa.io/get-pip.py', 'get-pip.py')", ], check=True, ) run([str(PY), "get-pip.py"], check=True) ``` Packages are then upgraded without exact versions or hashes: ```python def install_packages(packages: list[str]) -> None: """安装 Python 包""" print(f"\n[*] 安装 Python 包: {', '.join(packages)}") for pkg in packages: run( [ str(PY), "-m", "pip", "install", "--quiet", "--upgrade", pkg, ], check=True, ) ``` ```text openpyxl>=3.1.0 pyyaml>=6.0 playwright>=1.40.0 ``` The package also includes an encoded pip archive that is decoded and imported as executable Python code: ```python def main(): tmpdir = None try: # Create a temporary working directory tmpdir = tempfile.mkdtemp() # Unpack the zipfile into the temporary directory pip_zip = os.path.join(tmpdir, "pip.zip") with open(pip_zip, "wb") as fp: ...[truncated 2582 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shop_inspection_fresh_run_universal.py:37
Finding

Automatic Discovery and Execution of Untrusted External Python Projects

Content
View full analysis
list[Path]: roots: list[Path] = [] if explicit: roots.append(Path(explicit).resolve()) script_dir = Path(__file__).resolve().parent roots.extend( [ script_dir, script_dir / "shop_inspection", script_dir.parent / "shop_inspection", Path.cwd(), Path.cwd() / "shop_inspection", ] ) return roots def find_project_root(explicit: str | None) -> Path: for p in _candidate_project_roots(explicit): if (p / "main.py").exists() and (p / "config.yaml").exists(): return p raise SystemExit( "Cannot find project root.\n" "Please pass --project \"\"." ) ``` The discovered `main.py` is executed without provenance or integrity verification: ```python def run_inspection(py: Path, main_py: Path, config: Path, modules: str) -> None: cmd = [str(py), str(main_py), "--config", str(config)] if modules.strip(): cmd.extend(["--modules", modules.strip()]) code = run(cmd) if code != 0: raise SystemExit("inspection run failed.") ``` The main flow accepts the implicitly discovered project: ```python def main() -> int: args = parse_args() project_root = find_project_root(args.project or None) py = pick_python(project_root, args.python or None) main_py = project_root / "main.py" config = project_root / "config.yaml" state_dir = project_root / "state" seller_state = sta ...[truncated 2616 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose describes static instructional content/manual documentation. In contrast, the supplied code actively implements runtime configuration management for an automation tool: it searches for script files, loads JSON config from disk, resolves filesystem paths, and writes a default config file. This is a materially different primary purpose from a usage guide. Although the presence of a license file path loosely relates to activation mentioned in the description, the code itself is not presenting instructions; it is enabling application execution through configuration. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is documentation/instructions for customers, but the actual code is executable Python defining custom exceptions for an application. That is a materially different primary purpose. While the error classes may support a larger automation tool, this code chunk itself does not match the described manual content.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose describes static customer-facing usage documentation, but the supplied code is active operational logic for a system doctor/health check. Its primary purpose is to validate environment setup, dependencies, filesystem access, Playwright browser availability, and license validity for a Taobao automation tool. While some checks relate to installation and activation topics mentioned in the description, this is not documentation content; it is executable diagnostic behavior with file access, directory writes, imports, and subprocess execution. That constitutes a material mismatch between declared description and actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一份面向淘宝商家的使用说明文档,不应包含可执行的软件安装/bootstrap 逻辑。而实际代码是一个功能完整的 Python 安装引导器,其主要目的在于安装或升级 pip 及相关包,且会处理证书、临时文件、模块导入和软件安装流程。这与“说明文档”在目的、能力和行为上都明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says this skill is a usage manual with installation and purchase instructions. However, the provided chunk is a large block of unintelligible obfuscated data under scripts/get-pip.py, not human-readable documentation. Even without decoding it, its form and filename indicate programmatic/installer-related behavior rather than static explanatory content. That is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says this skill is a usage manual in Chinese for Taobao merchant automation customers, covering installation, activation, running steps, and purchase information. However, the provided code chunk is a Python file named scripts/get-pip.py whose contents are long high-entropy gibberish/encoded data, not human-readable documentation or instructional text. Because the actual content is opaque and appears executable or packed rather than a manual, the description does not accurately represent the supplied code. Even without decoding, the mismatch is material: a customer manual should be plain text/documentation, not an obfuscated script payload.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says this skill is a usage manual with installation and purchase instructions. However, the provided file is a Python script path named get-pip.py whose contents are unreadable high-entropy data, not Chinese instructional text or documentation. Even without fully decoding it, this is materially inconsistent with a customer-facing manual. The filename also suggests an installer/bootstrap script, which is unrelated to the declared purpose. Therefore the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is documentation/instructions for customers. However, the provided artifact is a Python file path containing an unreadable high-entropy blob, not human-readable Chinese documentation about installation, activation, or purchasing. Even if the blob were compressed or obfuscated code, that would still not match the declared purpose of being a usage manual. Therefore the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says this skill is documentation/instructions only, with no triggers or permissions. However, the actual content is a code file under scripts/get-pip.py and consists of large non-human-readable data, not Chinese user guidance, installation instructions, activation steps, or purchase info. Even without decoding it, the artifact is plainly not a documentation chunk. The filename also suggests a pip bootstrap/installer script, which is materially different from a Taobao merchant operation manual. Therefore this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the actual artifact. The description says this skill is documentation/instructions for users. However, the provided chunk is a file under scripts/get-pip.py and contains dense unreadable/obfuscated content, not human-readable installation or usage instructions. Even without decoding it, the primary purpose does not appear to be documentation. The filename also suggests a Python bootstrap/installer script, which is materially different from a static customer manual. Therefore the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says this skill is user documentation for Taobao merchant automation, with no triggers or permissions. However, the provided artifact is a massive unreadable blob under scripts/get-pip.py, not human-readable instructional content. Because the content is opaque, it cannot be confirmed as benign documentation and instead resembles encoded/compressed/binary script payload data. That is materially different from a customer usage manual and may conceal undeclared capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is purely informational documentation. However, the provided code chunk is not documentation text at all; it is an unreadable blob under a Python filename. Because the content is obfuscated or non-textual, its real behavior cannot be matched to the claimed purpose, and at minimum it is materially inconsistent with being a Taobao usage manual. This is a strong description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as informational documentation/customer instructions, but the supplied code is not documentation content—it actively modifies the system by installing Python packages and browser components, potentially downloading bootstrap files from the internet, and verifying execution capability. While installation is thematically related to the described product, the actual code’s primary purpose is operational environment setup rather than providing explanatory usage instructions. This is a material description-behavior mismatch because the code has active installer behavior and system-changing capabilities not reflected in the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一份使用说明/文档性质内容,不应包含可执行的授权校验逻辑。而实际代码是许可证控制模块,具备网络通信、本地文件持久化、设备指纹采集和卡密激活校验等功能。这些都属于实质性行为能力,不是单纯的“说明文字”。因此代码实际用途与声明用途明显不一致,存在重大描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a customer instruction/manual document about Taobao merchant automation, including installation, activation, operation, and purchase info. The actual code is not documentation at all; it implements a data-processing utility for parsing Taobao Excel reports into JSON. Its primary purpose is materially different from the declared purpose, and it has undeclared file input/output and transformation behavior. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose says this skill is documentation/instructions for using a Taobao merchant operations automation product. However, the supplied code does not implement user guidance, installation, activation, runtime instructions, or purchase-related behavior. Instead, it provides backend data-processing utilities: reading Excel files with openpyxl, extracting headers and rows, converting numeric fields, and evaluating formulas safely. This is a materially different primary purpose and includes undeclared capabilities related to spreadsheet parsing and expression computation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一份‘使用说明/文档’,不涉及任何可执行自动化能力,也未声明需要网站访问、浏览器控制、下载文件或本地持久化。实际代码则明确实现了淘宝生意参谋报表自动化采集与下载流程,核心目的与说明文档完全不同,属于明显的描述与行为不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes documentation/instructions for users, implying informational content only. The actual code is operational software: it parses CLI arguments, reads and writes configuration, checks dependencies, enforces licensing, exposes machine fingerprint and license status, and launches other Python scripts to execute a merchant workflow. While some described topics like installation and activation are related thematically, the primary purpose and capabilities are materially different. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes static user documentation/instructions, with no triggers or permissions. The actual code is an operational automation script that performs environment detection, dependency installation, credential/session bootstrapping, and execution of inspection tasks. This is a materially different primary purpose and includes active system capabilities not represented by the description.

Content

No source excerpt is available for this finding.

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/get-pip.py (reported line 23312)May include surrounding context.

python
n~g>n8bitT9FhDr$aRTs7r`hmW%B<?79K^`_|Y2mBAeoAOP!T&>sj`%
U@i_Ya2RM~79~I7-ath>wkhkOu*os^?xw>v%}<Q5%_F3r7eHD7ZHwBN}QkaJtmP9uGapYxiu0>3(SxR
!le7@oomK3~sM;v64zI>`VGfx+%>uR$P3ME+kZ<E-Un^0479^{H{-9T#q5@sTuORAiA_qkCVD|2;ML`
%iNRQXun2To^dVC@Rn0Qm#j!!*cxmqQ${gT2*ki3zf_|#ytI`k(-&EwN!-}3-+}=9CK<lc;RCAYwWm=
1I8yy^)u;AsFDJL&MZeo3;_KuOb1co0Zw>*giJj?}{ov$SLXBuYnDMjCl6}~I?A#qcfX>98GJfOFK7R
2*u^wEd##sL?F6;rWiq8irHTpSPy5l3=uxf&=Ds40#46>Kn-&f-Pa9oXB6}cdhOX3aWM;6gr2T%-NPb
ua2yJunG5q~5rOl=LrUD{95E*{R<(M0{yBX^)9apVuK!(qPtO~P2E+(PhH=+LS&tL^+E4zOo^xt(G*V
IbZ~35^Ai8hvK3s&r6w7?!!m$y;`BIuc9dD)k@+h~-DsxFcovu;7d<As-+_kK*qxZy#!V59>af$DhF8
5AgPJs5IeYOkTQgJ|zQpxZ}q3b?x1W)%E=|67oz$sM--q!#oM^M(m}t7f(M*Ke?hgTm|yJUdPAgKV)-
bv9jJzfBaFjIt@3GV^7p7i9PbhC~sqd8bV^(&r$I?!SfY+@ap?oZOTBq)x0Qsx=ys(FP-!wZPwHvJdu
s_4UxUr9~3`cLr1~lV=+3q$boyEqAkdK-&bOxh&wf@V<|tL2Ya+b&%iRY`c*0iSlu5-HkfX9>?&S-+3
r`soLWv$1bjw|zEh_zbraM07f?Oa035A+oTzxj)ioUZV~ZTCt9=IbW>5s-=^w7NSRwJT`iYBGaBjx)R
Y<iZzMFyG-Z;Fc<^(YD&!MmotY2O+at7fjJ?4|>Fds-XAEmb(rL!EVuN=@-=m^09

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/install.py (reported line 78)May include surrounding context.

python
cwd: Path | None = None,
) -> subprocess.CompletedProcess[bytes]:
    print(f"\n>>> {' '.join(cmd)}")
    merged_env = os.environ.copy()
    if env:
        merged_env.update(env)
    result = subprocess.run(

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/install.py (reported line 181)May include surrounding context.

python
cwd: Path | None = None,
) -> subprocess.CompletedProcess[bytes]:
    print(f"\n>>> {' '.join(cmd)}")
    merged_env = os.environ.copy()
    if env:
        merged_env.update(env)
    result = subprocess.run(

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script downloads get-pip.py from the internet and immediately executes it, which is a classic remote code execution and supply-chain risk. If the download source, TLS trust chain, local network path, or endpoint is compromised, arbitrary code can run with the user's privileges.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements active license enforcement, remote activation, and runtime authorization checks despite the skill being ներկայացված as customer instructions/documentation. This is a material mismatch between declared purpose and actual behavior, which increases the risk of hidden functionality and unexpected data flows to a third-party server.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata says this package is only a Taobao merchant operations usage/install guide, but the code actually launches Chromium, logs into Taobao business analytics, automates report generation, and downloads data. This functionality mismatch is dangerous because it hides active account operations and data extraction behind a documentation-only description, reducing user scrutiny and consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.