Back to skill

Security audit

EcomSeer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent EcomSeer analytics assistant, but it needs review because it stores pasted API keys and sends credentials, queries, and hosted reports through additional services without clear user control.

Before installing, treat this as a Review item. Use a dedicated, revocable EcomSeer API key with the least access available, avoid pasting secrets into chat where possible, and understand that Deep Research can automatically send your query, context, and API key to EcomSeer server-side infrastructure and produce a shareable hosted report link. Review the installer source/version before using the unpinned `npx` command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

other

Error
Location
SKILL.md:136
Finding

API Credential and User Context Forwarded to a Secondary Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:77
Finding

Shell Command Injection Through Direct Substitution of Chat-Controlled Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:140
Finding

Hardcoded Shared Bearer Token Embedded in Public Skill Instructions

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:158
Finding

Unbounded Polling Loop Can Indefinitely Consume Agent Resources

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Automatically configuring a persistently stored API key from chat input without a clear warning or explicit confirmation is unsafe secret handling. Users may unknowingly disclose credentials into logs/transcripts and may not realize the key is being stored for future use.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly encourages users to paste API keys into chat and then persists those secrets in configuration, violating the principle of minimizing secret exposure. Chat channels are often logged, reviewed, or retained, so this pattern substantially raises the risk of credential leakage and unauthorized reuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The deep research workflow forwards the user's EcomSeer API key to a separate service at deepresearch.ecomseer.com, which is a different trust boundary than the advertised API host. Forwarding credentials to another backend enables credential reuse, mishandling, logging, or compromise outside the user's expected scope, and the manifest does not clearly justify this delegation.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 351)May include surrounding context.

md
**Reuse data:** If the user asks follow-up questions about already-fetched data, analyze existing results first. Only make new API calls when needed.

## Output Guidelines

1. **Language consistency** — ALL output must match the user's detected language.
2. **Route-appropriate output** — Don't dump tables for browsing; don't skip data for analysis.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install ecomseer without pinning a specific version. This creates a supply-chain risk because the latest published package version will be executed at install time, and a compromised or malicious update could run arbitrary code on the user's machine. In the context of an install command in documentation, this is a real security issue even if likely unintentional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that Deep Research reports are 'hosted and shareable via link' but does not prominently warn users about the privacy and confidentiality implications. Generated reports may contain sensitive market research, shop comparisons, influencer analysis, or proprietary business strategy, and hosting them by default can expose that information through unintended sharing or discoverability. Given this skill's focus on commercial intelligence, the context increases the sensitivity of the hosted output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Deep Research activation criteria are described very broadly, including automatic triggering for queries requiring '2+ API calls or cross-entity reasoning.' This ambiguity can cause users to invoke a more expansive server-side processing mode than expected, increasing the chance that more data, context, or sensitive business queries are sent to hosted infrastructure without explicit, informed consent. In a data-intelligence skill handling commercial analysis, implicit escalation to deeper processing is more dangerous because users may assume they are doing simple lookups.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The installation command uses npx clawhub without pinning a specific version, so users may execute whatever package version is current at install time. This creates a supply-chain risk: a compromised upstream release or typosquatted dependency could run attacker-controlled code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that 'deep research' is automatically triggered for broad classes of queries, including any request requiring more than two API calls or cross-entity reasoning. Such vague activation criteria can cause users to unintentionally invoke a more powerful server-side workflow, increasing the chance of unexpected data processing, higher-cost actions, or transmission of sensitive business queries beyond what the user intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document says the feature uses a server-side AI research system and produces hosted, shareable online HTML reports, but it does not clearly warn users that their queries and possibly derived analysis data are sent off-platform and stored in a shareable form. In an e-commerce intelligence context, user prompts may contain sensitive market research, shop strategy, product plans, or competitor analysis, so undisclosed remote processing and link-based sharing materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description lists generic English triggers such as "find trending," "shop data," "product research," and "e-commerce analytics," along with short Chinese phrases like "带货" and "爆品." These are broad topical terms rather than narrowly scoped invocation phrases, which increases the chance of unintended activation during normal conversation about e-commerce.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to accept an API key pasted into chat and persist it into local configuration, expanding from data assistance into credential handling. This creates unnecessary secret exposure risk in chat history and local state, and can surprise users because persistence occurs automatically without explicit consent or secure input handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes analytics via ecomseer.com, but the implementation additionally relies on deepresearch.ecomseer.com and publishes reports on r2.dev, which materially changes the data-flow and hosting surface. This mismatch undermines informed consent and security review because user data and outputs may be sent to or hosted by services not declared in the skill description.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

Run this command first to verify the API key is valid:

bash
curl -s -o /dev/null -w "%{http_code}" "https://www.ecomseer.com/api/open/goods/filters?region=US" -H "X-API-Key: $ECOMSEER_API_KEY"
  • If it returns 200 → key is valid, proceed to Step 1.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill documentation is written only in Chinese, with no indication that users may choose another language or that the skill is intended exclusively for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly exposes an influencer contact-information subinterface and states that contact details may be returned, but it provides no privacy warning, access-control requirements, consent basis, or data-handling limitations. In an e-commerce intelligence skill, this increases the risk of harvesting personal contact data for unsolicited outreach, spam, or broader privacy misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown repeatedly sets region default values to US, which imposes a locale/market default in the skill documentation rather than presenting a user choice or documenting why the US locale is required. Under the policy, forcing a specific locale without opt-in can be a natural-language policy concern when no justification is given.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The documentation repeatedly sets region default values to US, establishing a locale-specific default behavior. Because no user choice, opt-in, or justification is provided in the natural-language description, this can be read as a locale policy issue under the language/locale policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents the skill/API documentation in Chinese by default, and there is no indication that users can choose another language or have opted into Chinese-only content. The policy explicitly calls for flagging language or locale constraints when a specific language is forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents the skill documentation entirely in Chinese, including headings, parameter descriptions, and cautions, without indicating that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the language/locale policy check, this is a natural-language policy concern because it imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown repeatedly specifies region with a default value of US, which imposes a locale/market default in the skill documentation. Under the policy, forcing a specific locale without user opt-in or clear justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This line defines region with a default of US, again creating a locale preference in the natural-language/API description. Because the file does not explain why US is mandatory or invite user selection, it may conflict with the language/locale policy guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The parameter table hard-codes US as the default target market, which is a locale choice expressed in natural language. The file does not state that this is optional user-configurable behavior or that the endpoint is limited to that locale for compliance or product reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Using US as the default region sets a locale preference in the documented behavior. The policy allows this only when the user is given a choice or when the locale restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This repeats the same locale defaulting pattern by setting region to US in the parameter table. Because the documentation does not present this as an opt-in or explain a US-only constraint, it may violate the locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:142