Back to skill

Security audit

test-publish-dev1

Security checks for vulnerabilities and agentic risk

Overview

This skill automates a real authenticated product-distribution action, but it embeds credentials, uses plaintext HTTP, and can submit even when required selections fail.

Review this before installing. It can log into a fixed remote service and trigger product-distribution actions automatically. Do not use it unless the endpoint and account are yours to operate, the password has been rotated out of source code, HTTPS and secret management are used, and submission is gated on validated selections plus explicit user confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_distribution.py:51
Finding

Hardcoded Credentials Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auto_distribution.py:88
Finding

User-Controlled Values Are Interpolated into Playwright Selectors

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_distribution.py:82
Finding

Submission Proceeds When Required Selections Fail

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose and workflow do not accurately disclose the actual behavior indicated by the referenced implementation, including hardcoded credential use, direct website login, UI automation, and local screenshot capture. This mismatch is dangerous because reviewers and users may authorize a seemingly simple product publishing skill without understanding that it performs sensitive authenticated actions and handles potentially sensitive data locally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s implemented behavior materially differs from the stated skill purpose: instead of publishing products to Ozon, it logs into an internal web service at a hardcoded IP, selects fields, and clicks a generic 'send' button. In an agent skill context, this mismatch is dangerous because it can cause unauthorized or unintended actions on an internal system while presenting itself as a benign e-commerce automation tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code executes a generic '.send-btn' click with no validation, preview, or confirmation of what the action will do. Because 'send' is a state-changing operation on an authenticated internal page, this can trigger irreversible or sensitive business actions unintentionally or under deceptive skill packaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description does not clearly warn users that it will directly control a browser and perform listing actions on an external commerce platform. That omission reduces informed consent and makes the skill more dangerous in context, because authenticated marketplace actions can change listings, publish products, or affect store operations with limited visibility to the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough that the skill may activate for ambiguous requests related to product publishing or synchronization without clear exclusion rules or stronger confirmation. In this context, that is risky because the skill can drive a browser to perform external e-commerce listing actions, so accidental activation could cause unauthorized or unintended store operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

文件头注释明确表示“新策略:使用JavaScript直接操作Vue组件”,这描述的是通过脚本直接调用前端组件/状态进行操作。实际实现中未见 evaluate、注入脚本或任何直接操作 Vue 组件的代码,而是普通的 page.fill 和 page.click 交互,这与文档说明形成直接不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically logs into a remote service using embedded credentials and proceeds without any interactive warning or approval. In a skill ecosystem, silent authenticated automation increases the risk of misuse, accidental invocation, and unauthorized access if the environment did not intend to permit that login flow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI description says the tool only operates dropdowns and takes a screenshot, but the script also performs automated login and triggers a 'send' action. This understatement of behavior is risky in an agent setting because operators may approve or invoke the skill without realizing it performs authenticated, state-changing actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and operational instructions are entirely in Chinese, which implicitly forces a specific language for interaction and documentation. There is no opt-in language selection or explanation that the skill is intentionally restricted to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description and all user-facing messages are entirely in Chinese, with no indication that the skill is region-specific or that users may opt into another language. This can violate language/locale policy when a skill imposes a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.