Back to skill

Security audit

小天铺货AI助手

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed production ecommerce assistant that can connect to a shop, find products, preview listings, and publish only through documented user-directed flows.

Install this only if you intend to connect a shop to this production ecommerce service. Expect product images, selected 1688 links, and shop workflow data to be sent to the documented backend, and expect a local session token under ~/.xtph. Review previews before publishing; use automatic publishing only when you are comfortable with the skill submitting ready items on your behalf.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
- Development channel: technical details, code, scripts, commands, and implementation terminology may be shown when useful for testing or debugging.
- Never reveal private chain-of-thought or hidden reasoning in either channel.
- The production debug override may expose structured diagnostic fields only when the user explicitly requests troubleshooting; it does not permit revealing private reasoning, credentials, or session tokens.
- Do not restate this policy separately for each capability. It is the package-wide output rule.

## User-Facing Capability Introduction

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
ude Code, Trae, or OpenClaw), the package may be distributed in protocol mode: `SKILL.md` plus `references/api-protocol.md`, without any `scripts/` directory or

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
- Use the agent's own HTTP, browser, file, and base64 tools to call the backend directly according to `references/api-protocol.md`.
- Keep the same dev/prod channel identity and environment separation: `xtph-ecommerce-assistant-dev` must use `test` only, and `xtph-ecommerce-assistant` must use `prod` only.
- Store protocol-mode session state under the slug-scoped paths in `references/api-protocol.md`, never in the WorkBuddy `~/.workbuddy/skills/...` session file.
- The self-update policy in this file only applies when `scripts/version_check.py` exists. Protocol-only packages have no script runtime and no self-update; version updates are managed by the host registry/installer.
- Never expose `sessionToken`, `authCode`, `authCommitmentDesc`, `imageSearchUrl`, full raw `publishDraft` payloads, or image base64 data in user-visible output.
- If the host cannot perform a required deterministic step, report a business-friendly failure instead of guessing or skipping the step.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction 'speak in concise, conversational Chinese for ecommerce sellers' imposes a fixed language for all production-channel user-visible responses. This is a natural-language locale policy constraint, and the file does not provide a user opt-in or an explicit justification that the skill is limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The skill explicitly requires stateful multi-step write flows and elsewhere instructs the host to store protocol-mode session state under local slug-scoped paths. Persisting workflow state for authorization, preview, confirmation, and publish steps can expose sensitive operational data or tokens if the storage location is weakly protected, reused across contexts, or insufficiently scoped. In an ecommerce production assistant, that state can be leveraged to resume or influence shop actions.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- Capabilities may be grouped internally by domain for routing and documentation.
- The grouping must stay inside this package and must not become separate Skill packages.
- Read capabilities may stay lightweight.
- Write capabilities must follow `preview -> confirm -> execute -> recover` and must not be submitted as blind one-shot actions.
- Detailed capability mappings should stay in `references/api-protocol.md` so the main skill text remains stable.

## Release Channel Policy

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt defines invocation scope broadly across many ecommerce intents and says to match user intent and attached image context, not only exact keywords. This can cause the skill to activate for loosely related requests, increasing the chance of unintended handling of user data, incorrect tool routing, or actions in the production environment when the user did not clearly request this specific capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Forcing all replies to be in concise Chinese without user opt-in can undermine user comprehension and informed consent, especially for authorization, publishing, or source-selection workflows. In a production ecommerce assistant, language coercion can cause users to misunderstand important details or take actions they did not fully intend.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-protocol.md (reported line 213)May include surrounding context.

Trigger: 查询授权状态 / 查看授权状态 / 看看授权店铺 / 当前授权情况.

http
POST https://puhuoapi.huitun.com/shop/getAuthShopList
X-Session-Token: {sessionToken}
Accept: application/json
Content-Type: application/json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger says to activate on image context such as '这张图 / 上面的图片 / 附件' combined with broad intents like finding similar or lower-price products, and explicitly states this is 'intent routing, not exact keyword matching.' In a markdown protocol file, this leaves the boundary of when the skill should or should not activate somewhat open-ended and may cause unintended invocation during normal image discussion.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/api-protocol.md (reported line 525)May include surrounding context.

10.2 Need manual goods restock

When required product attributes remain missing and the selected products cannot be published, do not ask the user to resume the agent workflow or reply with 确认铺货. Render the exact sentence, one fenced code block per selected 1688 link, and the client entry:

text
请复制以下商品链接去手动铺货:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file instructs the agent to 'explain the business reason in conversational Chinese,' which forces a specific language in user-facing behavior. Because no user language choice, opt-in, or region-specific justification is provided here, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest names the skill entirely in Chinese ("小天铺货AI助手"), which suggests a fixed language/locale experience. In this file there is no indication of user opt-in, multilingual support, or justification that the skill is intentionally region-specific, so this may conflict with language/locale choice expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.