Back to skill

Security audit

xianyu-product-manager-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but it can create real Xianyu listings through unsafe and batch paths and includes a hard-coded fallback account, so it should be reviewed before installation.

Install only if you intend to let this skill create Xianyu marketplace listings. Run dry_run first, always pass the intended user_name explicitly, avoid the _unsafe methods unless automation is tightly controlled, and use limited credentials so mistakes cannot affect a high-value account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
__init__.py:203
Finding

Hard-Coded Default Account Identifier Used in Product Write Operations

Content
View full analysis

Vulnerability Details

File Location: __init__.py, lines 203 and 219
Vulnerability Type: Hard-coded account identifier and fail-open account selection
Risk Level: Medium

Complete Code Snippet

python
# Default Xianyu account
actual_user_name = user_name or "xy137114666612"

return {
    "item_biz_type": 2,
    "sp_biz_type": 1,
    "channel_cat_id": self.channel_cat_id,
    "price": template['price'],
    "original_price": template['original_price'],
    "express_fee": 0,
    "stock": 20,
    "outer_id": f"AI-{service_type.upper()}-{price_tier.upper()}-{int(time.time())}",
    "stuff_status": 100,
    "province_id": 110000,
    "city_id": 110100,
    "district_id": 110101,
    "publish_shop": [{
        "user_name": actual_user_name,
        "images": images,
        "title": custom_title or template['title'],
        "content": custom_content or template['content'],
        "service_support": "SDR"
    }]
}

Technical Analysis

The generate_product_data() method accepts user_name as optional and silently substitutes the fixed identifier xy137114666612 when the caller omits it or supplies a false-like value. The resulting identifier is placed directly in the publish_shop section of the product payload.

This is a fail-open account-selection design. A write operation should require the caller to explicitly identify the intended account or derive that account from the authenticated API-client context. Falling back to an account identifier embedded in source code creates a confused-deputy risk: the credentials used by the underlying API client and the account named in the payload may not correspond to the caller's intended target.

The affected payload can reach both the confirmed create_product() route and the explicitly unconfirmed create_product_unsafe() route. Batch methods also inherit this behavior because they invoke the same payload-generation method.

Attack Path

  1. A caller invokes create_product(), `cre ...[truncated 1289 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded account identifier from the source code.
  2. Make user_name mandatory for every write operation and reject missing or blank values:
python
if not isinstance(user_name, str) or not user_name.strip():
    raise ValueError("user_name is required for product operations")

actual_user_name = user_name.strip()
  1. Prefer deriving the target account from the authenticated API-client context, where supported, rather than allowing an arbitrary payload field to select it.
  2. Verify that the requested account matches the identity authorized by the current API credentials before creating a product.
  3. Apply the same validation to single and batch operations, including unsafe methods.
  4. Add tests confirming that omitted, empty, and whitespace-only account identifiers fail closed before any API request.
  5. Avoid logging complete product payloads if account identifiers or other sensitive business information could be exposed.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims enforced confirmation and safe product creation, but its own Security Model explicitly documents _unsafe methods that bypass confirmation. That mismatch is dangerous because users and higher-level agents may rely on the safety claims while invoking write-capable paths that can create listings without an interactive checkpoint.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims enforced confirmation and safe product creation, but its own Security Model explicitly documents _unsafe methods that bypass confirmation. That mismatch is dangerous because users and higher-level agents may rely on the safety claims while invoking write-capable paths that can create listings without an interactive checkpoint.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims enforced confirmation and safe product creation, but its own Security Model explicitly documents _unsafe methods that bypass confirmation. That mismatch is dangerous because users and higher-level agents may rely on the safety claims while invoking write-capable paths that can create listings without an interactive checkpoint.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · xianyu_poster_generator.py (reported line 51)May include surrounding context.

python
prompts.append(prompt2)
    
    return prompts

def get_default_poster_prompts(service_category: str = "AI服务") -> List[str]:
    """

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation and all user interaction examples are presented exclusively in Chinese, and the workflow examples assume Chinese-language prompts and outputs. There is no statement offering a language choice or explaining that the skill is intentionally limited to Chinese-speaking users or the Xianyu market context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The documented _unsafe methods intentionally skip confirmation for write operations, enabling autonomous external side effects. In a skill that creates marketplace listings, bypassing user confirmation increases the risk of unauthorized postings, spam, accidental inventory changes, and abuse by upstream agents or prompt injection chains.

Content

Scanner excerpt · SKILL.md (reported line 281)May include surrounding context.

md
### Unsafe Methods (Explicit Opt-In)

For controlled automation, separately named `_unsafe` methods are provided (`create_product_unsafe`, `create_batch_products_unsafe`). These skip confirmation and should only be used after dry-run review with dedicated low-permission credentials.

### Batch Size Limit (Code-Enforced)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file contains user-facing natural-language docstrings and generated product descriptions exclusively in Chinese, including method documentation and listing content. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The method documentation and class-level safety comments claim that product creation requires user confirmation by default, but the implementation performs a live create operation whenever dry_run is false. This is a safety-control mismatch that can cause unintended external side effects, especially if an agent or operator relies on the documented confirmation behavior before invoking the function.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The batch method similarly claims default confirmation behavior but directly creates multiple live listings with no approval step. In batch context this is more dangerous because a mistaken invocation can trigger up to the hard cap of 20 external mutations, amplifying business, account, and operational impact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description states it is a generator for Chinese/Xianyu-style posters, and the prompt templates consistently require "Chinese poster" output. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring for generate_xianyu_poster_images says it returns a list of generated image URLs, implying actual image generation or remote image references. In reality, the function only constructs and returns prompt strings at L28-L51, which directly contradicts the documented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file's user-facing description and function docstring are entirely in Chinese, which imposes a specific language/locale in natural-language content without offering a language choice or documenting why the skill is region-specific. Under the policy, locale constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.