Back to skill

Security audit

PDD Shop Report

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Pinduoduo reporting tool, but its optional ClickHouse backend can send or query shop data through an arbitrary environment-configured URL while the manifest under-discloses external merchant-data flow.

Install only if you intend to use it for Pinduoduo shop reporting and understand its data paths. Keep PDD_CH_URL unset unless you deliberately use a trusted ClickHouse backend, preferably over HTTPS on a controlled host. Review report output paths before running because generated HTML files can overwrite the chosen destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tainted flow: 'req' from os.environ.get (line 150, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The ClickHouse endpoint is fully controlled by the PDD_CH_URL environment variable and is used directly in urllib.request.urlopen without validation, allowlisting, or transport security requirements. In an agent or shared runtime, a malicious or misconfigured environment can redirect shop data to an attacker-controlled host, enable SSRF to internal services, or silently exfiltrate business data.

Content

Scanner excerpt · scripts/store.py (reported line 151)May include surrounding context.

python
def _ch(sql, data=None):
    q = urllib.parse.urlencode({"query": sql, "default_format": "JSONEachRow"})
    req = urllib.request.Request(f"{CH_URL}/?{q}", data=data, method="POST" if data else "GET")
    return urllib.request.urlopen(req, timeout=30).read().decode()

def _ch_rows(sql):
    out = _ch(sql).strip()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable behavior that can read environment variables, access local files, write reports, and potentially send data over the network, but it does not declare any explicit tool scope or permission boundaries. That makes it harder for the platform or reviewers to enforce least privilege and increases the risk of unintended data exposure from local databases, shops.yaml, or configured remote endpoints like ClickHouse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger text is broad enough to activate on generic requests about shop status or operations overviews, which can cause the skill to run in contexts the user did not specifically intend. In a reporting skill tied to business data, overbroad invocation can expose more data than necessary or cause unnecessary file/network operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The style rules are written as mandatory instructions and constrain presentation format without offering the user a language or locale choice. This can violate language/locale policy expectations when users have not opted into Chinese-language interaction or locale-specific formatting requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The report output is explicitly marked with lang="zh" and all visible UI text is fixed in Chinese, which enforces a specific language locale. Under the stated policy, forcing a language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs a file write via the user-controlled --out path, creating or overwriting report output on disk. While the CLI usage mentions an output path, there is no confirmation prompt, log message before writing, or explicit warning comment/docstring near the write operation to disclose that local files will be modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cockpit view similarly declares lang="zh" and presents all interface text in Chinese only. This imposes a fixed locale without any visible opt-in or alternative, matching the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The cockpit() path also writes generated HTML to an output file, which is a safety-relevant filesystem modification. There is no confirmation prompt, pre-write notice, or nearby explanatory comment warning the user that the operation will create or overwrite a local file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module auto-switches to a remote ClickHouse backend when PDD_CH_URL is set, causing business data to leave the local machine without any disclosure in this file. In agent environments, this can surprise users and increase the risk of unintended data transfer to external infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs outbound HTTP requests that may transmit shop and goods snapshots to a remote database, but there is no visible user notification or confirmation at the point of transmission. Because the skill handles business and operational data, silent remote transfer raises confidentiality and compliance concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest content is presented entirely in Chinese and does not indicate any user language choice or opt-in. Under the policy criteria, a skill artifact that implicitly forces a specific language can be a locale-policy violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill's stated purpose is to generate PDD shop reports from data synced by pdd-sync-shop. In addition to using synced store data, the cockpit feature reads a separate local registry file (shops.yaml) and honors PDD_DATA_DIR from the environment to derive display labels, which is not an obvious requirement of report generation itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's natural-language documentation and multiple user-facing messages are entirely in Chinese, which imposes a locale choice on users without opt-in. The policy allows locale constraints only when user choice is offered or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.