Back to skill

Security audit

国内电商全链路运营

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Chinese e-commerce toolkit, but its live-data workflow can turn untrusted JSON values into executable shell command text without validation or quoting.

Review before installing. The calculators themselves look ordinary, but do not execute live.py generated commands from untrusted or web-derived live_data.json without validating and shell-quoting every value. Treat live WebSearch/WebFetch mode as sending business-sensitive product, pricing, supplier, and platform terms to external sites.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a comprehensive multi-tool e-commerce operations skill with live data integration across multiple platforms. The actual code chunk is much narrower: it is a single ad ROI/CPC calculator script. While this script does align with one subset of the declared functionality—广告投放ROI测算—it does not implement the majority of the described capabilities, especially the real-time data bridge and the other six calculators/tools. There is no network access, no compliance checking, no title generation, no inventory planning, and no funnel diagnosis in the provided code. Therefore the supplied code does not accurately represent the declared overall skill behavior, making this a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is narrowly focused on one sub-capability mentioned in the description: advertising/compliance term checking for e-commerce copy. That part is aligned. However, the declared purpose presents the skill as a comprehensive e-commerce operations suite with multiple calculators and a real-time data connector, while this code provides none of those functions. There is no network access, no web search/fetch integration, no platform-specific operational logic, no pricing/profit/ROI/funnel/inventory computation, and no title generation. Therefore the supplied code materially underdelivers relative to the declared description, making the description inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad, action-oriented e-commerce operations toolkit with multiple analytical calculators and live market-data ingestion. The actual code chunk does not implement those capabilities. It only defines static fee references for several platforms and some generic benchmark ranges, with simple formatting/access utilities. While static platform fee data could support a larger pricing/profit tool, this chunk by itself is much narrower in purpose and lacks the claimed live fetching, computation, compliance checking, title generation, and inventory planning behavior. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
73% confidence
Finding

The skill is presented entirely as a Chinese-language "国内电商" skill and does not mention any user language choice or opt-in behavior. While the domain is China e-commerce, the file does not explicitly state that the locale restriction is intentional and region-specific, which can create a language/locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes automatic triggering but does not clearly define when the skill should not activate, especially for adjacent topics like general copywriting, platform advice, or broad e-commerce strategy. Ambiguous activation boundaries increase the chance of overreach: the agent may invoke calculators or live-data workflows when the user only wanted discussion, causing incorrect assumptions, extra external fetches, or confusion about the source of answers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README describes automatic triggering but does not clearly define when the skill should not activate, especially for adjacent topics like general copywriting, platform advice, or broad e-commerce strategy. Ambiguous activation boundaries increase the chance of overreach: the agent may invoke calculators or live-data workflows when the user only wanted discussion, causing incorrect assumptions, extra external fetches, or confusion about the source of answers.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly directs use of WebSearch/WebFetch and executable Python scripts, but the manifest does not declare any tool scope, permissions, or allowed-tools restrictions. This creates an overbroad capability surface where the runtime may grant file, shell, and network access without user-visible least-privilege boundaries, increasing the chance of unintended data access or outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill repeatedly instructs the agent to use WebSearch/WebFetch to retrieve live commission rates, return rates, supplier pricing, and keyword volumes, but it does not clearly warn that user queries and business parameters may be transmitted to third-party sites. This can expose commercially sensitive product ideas, pricing assumptions, platform strategy, or supplier interests to external services without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, common business phrases, which can cause the skill to activate for loosely related conversations. In a skill that encourages network fetching of live data and use of calculation scripts, accidental invocation can lead to unnecessary external requests, data exposure of user business context, or over-application of the skill outside intended scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing guidance solely in Chinese, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the natural-language policy rule, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file begins with a Chinese-only title and the entire playbook is written in Chinese, with no indication that language selection is optional or that the skill is intended solely for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions, descriptions, and warnings exclusively in Chinese, and the CLI/help text and rendered report are likewise fixed to Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains user-facing natural-language documentation entirely in Chinese and presents the tool as a Chinese-language skill, with no indication that users may select another language. The policy for this audit flags language or locale constraints when they are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing CLI messages are written in Chinese, establishing a fixed language for interaction. For a general-purpose inventory calculator, this is a natural-language locale constraint without any documented opt-in, fallback, or user-selectable language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring, command descriptions, and user-facing output are entirely in Chinese, effectively imposing a specific language/locale on all users. The file does not offer any opt-in, alternative locale, or explicit justification that this skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural language entirely in Chinese, including the module description and CLI help text, which effectively enforces a specific language for all users. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains its primary documentation and runtime status messages entirely in Chinese, including usage instructions and pass/fail summaries. That imposes a specific language on users without any visible opt-in or alternate locale handling, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/run_all.py (reported line 53)May include surrounding context.

python
def run(args: list[str], cwd: str = SCRIPTS):
    """执行子进程,返回 (returncode, stdout+stderr)。"""
    p = subprocess.run(
        [PY] + args, cwd=cwd, capture_output=True,
        text=True, encoding="utf-8", errors="replace",
    )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

描述以“国内电商全链路运营专家技能”为定位,全文默认使用中文平台语境与中文文案场景,且未说明是否支持其他语言或允许用户自行选择输出语言。按照语言/locale 政策,若技能对语言环境作出默认强约束而无选择机制,属于自然语言层面的潜在策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language note is entirely in Chinese and assumes use of China-specific platforms and tooling references such as 抖店规则中心、1688、义乌购、巨量算数、生意参谋. For a general-purpose skill/config file, this creates a locale-specific constraint without any stated user opt-in or documented justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This skill content forces a specific language for all instructions, and the file does not offer user opt-in or explain that it is intentionally limited to a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python skill hard-codes its natural-language interface entirely in Chinese, including the module description, CLI help text, errors, and rendered report output. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code file contains natural-language documentation, help text, error messages, and output labels exclusively in Chinese. Under the language/locale policy, forcing a single language without user opt-in can be a policy violation when no alternative locale or language selection is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.