T09 · Insecure Skill Coding Practices
- Location
__init__.py:203- Finding
Hard-Coded Default Account Identifier Used in Product Write Operations
- Content
View full analysis
Vulnerability Details
File Location:
__init__.py, lines 203 and 219
Vulnerability Type: Hard-coded account identifier and fail-open account selection
Risk Level: MediumComplete Code Snippet
python # Default Xianyu account actual_user_name = user_name or "xy137114666612" return { "item_biz_type": 2, "sp_biz_type": 1, "channel_cat_id": self.channel_cat_id, "price": template['price'], "original_price": template['original_price'], "express_fee": 0, "stock": 20, "outer_id": f"AI-{service_type.upper()}-{price_tier.upper()}-{int(time.time())}", "stuff_status": 100, "province_id": 110000, "city_id": 110100, "district_id": 110101, "publish_shop": [{ "user_name": actual_user_name, "images": images, "title": custom_title or template['title'], "content": custom_content or template['content'], "service_support": "SDR" }] }Technical Analysis
The
generate_product_data()method acceptsuser_nameas optional and silently substitutes the fixed identifierxy137114666612when the caller omits it or supplies a false-like value. The resulting identifier is placed directly in thepublish_shopsection of the product payload.This is a fail-open account-selection design. A write operation should require the caller to explicitly identify the intended account or derive that account from the authenticated API-client context. Falling back to an account identifier embedded in source code creates a confused-deputy risk: the credentials used by the underlying API client and the account named in the payload may not correspond to the caller's intended target.
The affected payload can reach both the confirmed
create_product()route and the explicitly unconfirmedcreate_product_unsafe()route. Batch methods also inherit this behavior because they invoke the same payload-generation method.Attack Path
- A caller invokes
create_product(), `cre ...[truncated 1289 chars]
- A caller invokes
- Remediation
View remediation
Remediation Suggestions
- Remove the hard-coded account identifier from the source code.
- Make
user_namemandatory for every write operation and reject missing or blank values:
python if not isinstance(user_name, str) or not user_name.strip(): raise ValueError("user_name is required for product operations") actual_user_name = user_name.strip()- Prefer deriving the target account from the authenticated API-client context, where supported, rather than allowing an arbitrary payload field to select it.
- Verify that the requested account matches the identity authorized by the current API credentials before creating a product.
- Apply the same validation to single and batch operations, including unsafe methods.
- Add tests confirming that omitted, empty, and whitespace-only account identifiers fail closed before any API request.
- Avoid logging complete product payloads if account identifiers or other sensitive business information could be exposed.
