other
- Location
SKILL.md:136- Finding
API Credential and User Context Forwarded to a Secondary Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent EcomSeer analytics assistant, but it needs review because it stores pasted API keys and sends credentials, queries, and hosted reports through additional services without clear user control.
Before installing, treat this as a Review item. Use a dedicated, revocable EcomSeer API key with the least access available, avoid pasting secrets into chat where possible, and understand that Deep Research can automatically send your query, context, and API key to EcomSeer server-side infrastructure and produce a shareable hosted report link. Review the installer source/version before using the unpinned `npx` command.
SKILL.md:136API Credential and User Context Forwarded to a Secondary Service
SKILL.md:77Shell Command Injection Through Direct Substitution of Chat-Controlled Values
SKILL.md:140Hardcoded Shared Bearer Token Embedded in Public Skill Instructions
SKILL.md:158Unbounded Polling Loop Can Indefinitely Consume Agent Resources
README.md:18Unpinned Package Execution Through npx Installation Command
Automatically configuring a persistently stored API key from chat input without a clear warning or explicit confirmation is unsafe secret handling. Users may unknowingly disclose credentials into logs/transcripts and may not realize the key is being stored for future use.
The skill explicitly encourages users to paste API keys into chat and then persists those secrets in configuration, violating the principle of minimizing secret exposure. Chat channels are often logged, reviewed, or retained, so this pattern substantially raises the risk of credential leakage and unauthorized reuse.
The deep research workflow forwards the user's EcomSeer API key to a separate service at deepresearch.ecomseer.com, which is a different trust boundary than the advertised API host. Forwarding credentials to another backend enables credential reuse, mishandling, logging, or compromise outside the user's expected scope, and the manifest does not clearly justify this delegation.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
**Reuse data:** If the user asks follow-up questions about already-fetched data, analyze existing results first. Only make new API calls when needed.
## Output Guidelines
1. **Language consistency** — ALL output must match the user's detected language.
2. **Route-appropriate output** — Don't dump tables for browsing; don't skip data for analysis.
The README instructs users to run npx clawhub install ecomseer without pinning a specific version. This creates a supply-chain risk because the latest published package version will be executed at install time, and a compromised or malicious update could run arbitrary code on the user's machine. In the context of an install command in documentation, this is a real security issue even if likely unintentional.
The README states that Deep Research reports are 'hosted and shareable via link' but does not prominently warn users about the privacy and confidentiality implications. Generated reports may contain sensitive market research, shop comparisons, influencer analysis, or proprietary business strategy, and hosting them by default can expose that information through unintended sharing or discoverability. Given this skill's focus on commercial intelligence, the context increases the sensitivity of the hosted output.
The Deep Research activation criteria are described very broadly, including automatic triggering for queries requiring '2+ API calls or cross-entity reasoning.' This ambiguity can cause users to invoke a more expansive server-side processing mode than expected, increasing the chance that more data, context, or sensitive business queries are sent to hosted infrastructure without explicit, informed consent. In a data-intelligence skill handling commercial analysis, implicit escalation to deeper processing is more dangerous because users may assume they are doing simple lookups.
The installation command uses npx clawhub without pinning a specific version, so users may execute whatever package version is current at install time. This creates a supply-chain risk: a compromised upstream release or typosquatted dependency could run attacker-controlled code on the user's machine during installation.
The README states that 'deep research' is automatically triggered for broad classes of queries, including any request requiring more than two API calls or cross-entity reasoning. Such vague activation criteria can cause users to unintentionally invoke a more powerful server-side workflow, increasing the chance of unexpected data processing, higher-cost actions, or transmission of sensitive business queries beyond what the user intended.
The document says the feature uses a server-side AI research system and produces hosted, shareable online HTML reports, but it does not clearly warn users that their queries and possibly derived analysis data are sent off-platform and stored in a shareable form. In an e-commerce intelligence context, user prompts may contain sensitive market research, shop strategy, product plans, or competitor analysis, so undisclosed remote processing and link-based sharing materially increases confidentiality risk.
The manifest description lists generic English triggers such as "find trending," "shop data," "product research," and "e-commerce analytics," along with short Chinese phrases like "带货" and "爆品." These are broad topical terms rather than narrowly scoped invocation phrases, which increases the chance of unintended activation during normal conversation about e-commerce.
The skill instructs the agent to accept an API key pasted into chat and persist it into local configuration, expanding from data assistance into credential handling. This creates unnecessary secret exposure risk in chat history and local state, and can surprise users because persistence occurs automatically without explicit consent or secure input handling.
The manifest describes analytics via ecomseer.com, but the implementation additionally relies on deepresearch.ecomseer.com and publishes reports on r2.dev, which materially changes the data-flow and hosting surface. This mismatch undermines informed consent and security review because user data and outputs may be sent to or hosted by services not declared in the skill description.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Run this command first to verify the API key is valid:
curl -s -o /dev/null -w "%{http_code}" "https://www.ecomseer.com/api/open/goods/filters?region=US" -H "X-API-Key: $ECOMSEER_API_KEY"
200 → key is valid, proceed to Step 1.The entire skill documentation is written only in Chinese, with no indication that users may choose another language or that the skill is intended exclusively for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The documentation explicitly exposes an influencer contact-information subinterface and states that contact details may be returned, but it provides no privacy warning, access-control requirements, consent basis, or data-handling limitations. In an e-commerce intelligence skill, this increases the risk of harvesting personal contact data for unsolicited outreach, spam, or broader privacy misuse.
The markdown repeatedly sets region default values to US, which imposes a locale/market default in the skill documentation rather than presenting a user choice or documenting why the US locale is required. Under the policy, forcing a specific locale without opt-in can be a natural-language policy concern when no justification is given.
The documentation repeatedly sets region default values to US, establishing a locale-specific default behavior. Because no user choice, opt-in, or justification is provided in the natural-language description, this can be read as a locale policy issue under the language/locale policy rule.
This markdown file presents the skill/API documentation in Chinese by default, and there is no indication that users can choose another language or have opted into Chinese-only content. The policy explicitly calls for flagging language or locale constraints when a specific language is forced without user opt-in.
This markdown file presents the skill documentation entirely in Chinese, including headings, parameter descriptions, and cautions, without indicating that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the language/locale policy check, this is a natural-language policy concern because it imposes a specific language without opt-in.
The markdown repeatedly specifies region with a default value of US, which imposes a locale/market default in the skill documentation. Under the policy, forcing a specific locale without user opt-in or clear justification can be a natural-language policy violation.
This line defines region with a default of US, again creating a locale preference in the natural-language/API description. Because the file does not explain why US is mandatory or invite user selection, it may conflict with the language/locale policy guidance.
The parameter table hard-codes US as the default target market, which is a locale choice expressed in natural language. The file does not state that this is optional user-configurable behavior or that the endpoint is limited to that locale for compliance or product reasons.
Using US as the default region sets a locale preference in the documented behavior. The policy allows this only when the user is given a choice or when the locale restriction is clearly justified, neither of which is present here.
This repeats the same locale defaulting pattern by setting region to US in the parameter table. Because the documentation does not present this as an opt-in or explain a US-only constraint, it may violate the locale policy criterion.
Detected: suspicious.exposed_secret_literal