Back to skill

Security audit

Noon 商品搜索工具

Security checks for vulnerabilities and agentic risk

Overview

This Noon search skill mostly does product scraping, but it asks for or uses browser control settings that are broader and less transparent than a simple search tool needs.

Review this skill before installing. Use it only in a disposable browser profile or isolated environment, avoid opening your normal Chrome profile with remote debugging enabled, and expect it to perform broader automated scraping than the documentation’s “first page” wording suggests.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
simple-search.js:6
Finding

Chromium Browser Sandbox Explicitly Disabled

Content
View full analysis

Vulnerability Details

File Location: simple-search.js, lines 6–9
Vulnerability Type: Browser process isolation disabled
Risk Level: Medium

Vulnerable Code

js
const browser = await puppeteer.launch({
  headless: true,
  args: ['--no-sandbox', '--disable-setuid-sandbox']
});

Technical Analysis

The Puppeteer launch configuration passes both --no-sandbox and --disable-setuid-sandbox to Chromium. These options disable Chromium's process sandbox and setuid sandbox, removing important isolation boundaries between browser-rendered content and the host operating system.

The script subsequently navigates this unsandboxed browser to Noon:

js
await page.goto(url, { waitUntil: 'networkidle2', timeout: 30000 });

The browser therefore processes content supplied by Noon and any third-party resources loaded by that site without Chromium's normal sandbox protections. Disabling the sandbox does not independently provide remote code execution, but it can substantially increase the impact of a browser vulnerability by eliminating an isolation layer that an attacker would otherwise need to escape.

Successful exploitation requires malicious or compromised web content and a compatible Chromium renderer or browser-process vulnerability.

Attack Path

  1. A user executes simple-search.js.
  2. The script launches Chromium with both sandbox mechanisms disabled.
  3. Chromium visits Noon and loads first-party and potentially third-party web resources.
  4. An attacker compromises an upstream resource, controls content returned to the browser, or otherwise causes the browser to process a malicious payload.
  5. The malicious content exploits a vulnerability in the installed Chromium version.
  6. Because browser sandboxing is disabled, successful exploitation may execute code with the privileges of the account running the Skill rather than remaining confined to a restricted renderer sandbox.

Impact Assessment

An attacker who successfully ...[truncated 822 chars]

Remediation
View remediation

Remediation Suggestions

Remove the sandbox-disabling command-line arguments and launch Chromium with its default security boundaries:

js
const browser = await puppeteer.launch({
  headless: true
});

Apply the following additional hardening measures:

  1. Run the Skill as a dedicated, unprivileged operating-system user.
  2. Never run the browser or Skill as root.
  3. Ensure the host supports Chromium's user-namespace or setuid sandbox configuration.
  4. Keep Chromium and Puppeteer dependencies updated with current security patches.
  5. If sandboxing cannot be enabled due to platform constraints, run the entire Skill in a disposable, tightly restricted container or virtual machine.
  6. Give that environment a read-only or minimal filesystem, no mounted secrets, restricted outbound networking, dropped Linux capabilities, and appropriate seccomp or mandatory-access-control policies.
  7. Allow navigation only to expected HTTPS origins where operationally feasible.
  8. Close the browser in a finally block to ensure cleanup after navigation or parsing failures.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

A tool advertised as accepting an Arabic keyword but actually using a hardcoded term is a trust and integrity problem: the user cannot rely on the advertised input boundary or output relevance. While not automatically code-execution dangerous on its own, this kind of undisclosed behavior is a strong indicator that the skill may not be doing only what it claims and can mask other unauthorized automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A tool advertised as accepting an Arabic keyword but actually using a hardcoded term is a trust and integrity problem: the user cannot rely on the advertised input boundary or output relevance. While not automatically code-execution dangerous on its own, this kind of undisclosed behavior is a strong indicator that the skill may not be doing only what it claims and can mask other unauthorized automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A tool advertised as accepting an Arabic keyword but actually using a hardcoded term is a trust and integrity problem: the user cannot rely on the advertised input boundary or output relevance. While not automatically code-execution dangerous on its own, this kind of undisclosed behavior is a strong indicator that the skill may not be doing only what it claims and can mask other unauthorized automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description and usage instructions require "阿拉伯语关键词" and describe the tool as searching with Arabic keywords, but they do not present this as an optional user choice or explain why Arabic is mandatory. This is a natural-language locale policy concern because the skill imposes a specific language constraint without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill enables puppeteer-extra stealth features and disables AutomationControlled despite only performing ordinary product search. Anti-detection mechanisms are risky because they conceal automation from the target site, can facilitate terms-of-service evasion, and are commonly associated with scraping patterns that bypass platform controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code uses Chinese-only user-facing messages throughout logs, errors, and usage instructions, such as at L009, L151-L152, and L159-L183. The skill does not provide any opt-in or fallback language selection, which is a natural-language locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code explicitly clicks 'load more' repeatedly and performs extensive scrolling, which expands collection beyond the stated 'first page' scope in the skill description. This is a scope-deception issue: consumers may authorize a limited product-search action but the implementation gathers a larger dataset than declared, increasing compliance, trust, and operational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code fixes both the query language ('لغز ممغنط') and the regional site path ('/saudi-ar/'), which imposes a specific language/locale behavior on users. There is no indication of user opt-in, configurability, or documentation justifying this locale restriction as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code sets the search keyword to the Arabic phrase 'لغز ممغنط' with no option for user selection or locale override. This creates a natural-language/locale constraint that is not presented as optional or justified as region-specific behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.