Back to skill

Security audit

小天铺货AI助手(开发版)

Security checks for vulnerabilities and agentic risk

Overview

This development ecommerce assistant is coherent with its stated purpose: it connects to a shop, searches 1688 sources, and can publish products through disclosed preview/confirmation or explicit auto-publish flows.

Install only if you are comfortable connecting a shop account to this development/test ecommerce assistant. It stores a local session token and saved preview workflows, sends product images or image URLs to the configured backend for 1688 sourcing, and can publish ready items when you confirm or explicitly request automatic publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
- Development channel: technical details, code, scripts, commands, and implementation terminology may be shown when useful for testing or debugging.
- Never reveal private chain-of-thought or hidden reasoning in either channel.
- The production debug override may expose structured diagnostic fields only when the user explicitly requests troubleshooting; it does not permit revealing private reasoning, credentials, or session tokens.
- Do not restate this policy separately for each capability. It is the package-wide output rule.

## User-Facing Capability Introduction

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
ude Code, Trae, or OpenClaw), the package may be distributed in protocol mode: `SKILL.md` plus `references/api-protocol.md`, without any `scripts/` directory or

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
- Use the agent's own HTTP, browser, file, and base64 tools to call the backend directly according to `references/api-protocol.md`.
- Keep the same dev/prod channel identity and environment separation: `xtph-ecommerce-assistant-dev` must use `test` only, and `xtph-ecommerce-assistant` must use `prod` only.
- Store protocol-mode session state under the slug-scoped paths in `references/api-protocol.md`, never in the WorkBuddy `~/.workbuddy/skills/...` session file.
- The self-update policy in this file only applies when `scripts/version_check.py` exists. Protocol-only packages have no script runtime and no self-update; version updates are managed by the host registry/installer.
- Never expose `sessionToken`, `authCode`, `authCommitmentDesc`, `imageSearchUrl`, full raw `publishDraft` payloads, or image base64 data in user-visible output.
- If the host cannot perform a required deterministic step, report a business-friendly failure instead of guessing or skipping the step.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L029 explicitly requires the assistant to "speak in concise, conversational Chinese" for production responses. This is a natural-language locale policy constraint, and the file does not present it as optional or user-selectable, nor justify it as a documented region-specific limitation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill explicitly requires multi-step write workflows and later instructs the host to store protocol-mode session state under slug-scoped paths. Persisting workflow state, authorization context, and selected items across steps creates a real session-persistence surface: if stored insecurely or without isolation, another local process, user, or skill could tamper with or reuse that state to publish items or access shop context. The ecommerce context increases sensitivity because persisted state may influence authenticated publish actions and authorization flows.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- Capabilities may be grouped internally by domain for routing and documentation.
- The grouping must stay inside this package and must not become separate Skill packages.
- Read capabilities may stay lightweight.
- Write capabilities must follow `preview -> confirm -> execute -> recover` and must not be submitted as blind one-shot actions.
- Detailed capability mappings should stay in `references/api-protocol.md` so the main skill text remains stable.

## Release Channel Policy

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name and display name are entirely in Chinese, and the manifest provides no indication that language is selectable or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, a fixed language/locale without user opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default_prompt activates the skill for broad 'ecommerce intent' based on loose intent matching and image context, without clear user opt-in or stricter routing boundaries. This can cause the skill to be invoked for ambiguous requests, increasing the chance of unintended access to shop-related workflows, misrouting user data or images into the test-environment skill, and producing actions outside the user's expectation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The prompt hard-codes a fixed seller-facing capability introduction and prescriptive output format, which may override user preferences for language, tone, or response style. While not directly enabling code execution or data exfiltration, this reduces user control and can mislead users in multilingual contexts or cause the agent to respond in an unsuitable register.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-protocol.md (reported line 213)May include surrounding context.

Trigger: 查询授权状态 / 查看授权状态 / 看看授权店铺 / 当前授权情况.

http
POST https://puhuoapi.huitun.com/shop/getAuthShopList
X-Session-Token: {sessionToken}
Accept: application/json
Content-Type: application/json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The activation text says to trigger on 'intent plus available image context' and includes very common references like '这张图' or '上面的图片' combined with broad shopping intents. Without clearer boundaries or exclusion examples, this could overlap with ordinary conversation about images and cause unintended invocation of the image-search flow.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/api-protocol.md (reported line 525)May include surrounding context.

10.2 Need manual goods restock

When required product attributes remain missing and the selected products cannot be published, do not ask the user to resume the agent workflow or reply with 确认铺货. Render the exact sentence, one fenced code block per selected 1688 link, and the client entry:

text
请复制以下商品链接去手动铺货:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly instructs the agent to explain business reasons 'in conversational Chinese,' which imposes a specific language on users. There is no accompanying opt-in, language preference check, or documented region-specific justification in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The preview entry includes several trigger phrases and then extends activation to 'the user-selected products from image search,' which leaves the invocation boundary somewhat implicit. The description does not provide exclusion conditions or a strict rule for when selection context should or should not start preview generation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.