Back to skill

Security audit

极鲸云 Shein 品类搜索&分析

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its SHEIN category-search purpose, but it handles login tokens and authentication links in ways users should review before installing.

Install only if you trust GeekBI and are comfortable with the skill storing reusable login tokens locally. Review and clean the .geekbi/agent-auth.json copies in your user config, skill directory, and working directory when you are done, and do not follow unexpected login links or instructions shown from service messages unless the destination is clearly trusted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shein_category_search.py:141
Finding

<![CDATA[Unrestricted Base URL Can Route Authentication Traffic to Untrusted or Plaintext Endpoints]]>

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/geekbi_auth.py:65
Finding

<![CDATA[Plaintext Bearer Tokens Are Replicated into Project and Working Directories]]>

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
references/查询暂停与恢复流程.md:3
Finding

<![CDATA[Unvalidated Server-Controlled Messages and URLs Are Published as Trusted Agent Output]]>

Content
View full analysis
- First run the category search script directly. The script uses `scripts/geekbi_auth.py` to prioritize the system user configuration login state shared by all GeekBI Skills; when a valid login state exists, login must not be requested again. - Only when the script returns `actionRequired` or exit code `2`, read and execute the pause-and-resume process. Display the server-provided Chinese message and valid redirect link to the user, then pause the query. - For exit code `1`, only display the top-level Chinese `msg` from the error output. ``` ```markdown The business script performs the query normally. When the server returns an operation address in `data.jumpUrl`: 1. Use the server-provided Chinese `msg` verbatim without changing its meaning. 2. Display `jumpUrl` as a clickable Markdown link without generating or rewriting it. 3. Stop the data query. 4. After the user completes the operation or replies to continue, rerun the original business request unchanged. 5. If the condition remains unsatisfied, use the latest server message. ``` ```python # scripts/geekbi_auth.py:497-509 def _raise_action_if_needed(payload): data = payload.get("data", {}) if isinstance(payload, dict) else {} jump_url = data.get("jumpUrl") if isinstance(data, dict) else None if not isinstance(jump_url, str) or not jump_url: return raise ActionRequired( response_message(payload, "请完成页面操作后继续"), jump_url, action=data.get("error") or "ACTION_REQUIRED", expires_in=int(data.get("expiresIn", 0)), ) ``` ```python # scripts/geekbi_auth.py:672-693 data ...[truncated 3335 chars]
Remediation
View remediation
The service reports that additional action is required. 6. Strip Markdown, HTML, control characters, and command-like formatting from remote messages. 7. Use a fixed, locally defined link label and display the validated destination hostname. 8. Never follow instructions inside remote messages that request command execution, file upload, credential disclosure, or safety-policy changes. 9. Bind authentication challenges to the expected API and login origins. 10. Add tests for `javascript:`, `file:`, `data:`, plaintext HTTP, deceptive user-info URLs, Unicode hostname confusion, and unapproved HTTPS hosts. ]]>

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

<![CDATA[Dependency Installation Is Not Reproducible or Hash-Verified]]>

Content
View full analysis
=4.0,<5.0 ``` ```markdown If the environment has not installed the dependencies, run `python3 -m pip install -r requirements.txt` before executing the query script. ``` ### Technical Analysis The dependency manifest permits any `platformdirs` release from version 4.0 up to, but excluding, 5.0. It does not provide: - An exact audited version. - Package hashes. - A lock file. - A trusted package index configuration. - Provenance or signature verification. As a result, installations performed at different times can resolve to different artifacts. If the upstream account, package distribution channel, configured index, or a permitted future release is compromised, the installation can introduce attacker-controlled code. No evidence was found that `platformdirs` itself is malicious. The confirmed issue is the absence of reproducible dependency and integrity controls, not the presence of a known malicious package. ### Attack Path 1. The Skill runs in an environment where dependencies are missing. 2. The documented workflow invokes: ```bash python3 -m pip install -r requirements.txt ``` 3. `pip` resolves the newest available package version satisfying `>=4.0,<5.0`. 4. A compromised package repository, malicious configured mirror, compromised upstream release, or substituted distribution serves a manipulated artifact. 5. The artifact is installed into the Skill environment. 6. Malicious package code can execute during installation or when `platformdirs` is imported by `scripts/geekbi_auth.py`. ### Impact Assessment Compromise of the dependency installation path could result in code execution with the privileges of the user or agent running `pip`. That scope could includ ...[truncated 428 chars]
Remediation
View remediation
``` 2. Generate and enforce cryptographic hashes: ```text platformdirs== \ --hash=sha256: ``` 3. Install with: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Use a lock-generation process that records exact transitive dependencies and hashes. 5. Configure an approved HTTPS package index and disable untrusted extra indexes. 6. Review and update pinned dependencies through a controlled process with vulnerability and provenance checks. 7. Consider replacing the dependency with standard-library platform-path logic if the small dependency is not necessary. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to perform SHEIN category search and analysis, but the detected implementation reportedly resolves site information instead of category data and does not provide the advertised category identifiers, hierarchy, or filtering features. While this is not a classic exploit primitive by itself, such misrepresentation is dangerous because it can mislead operators into granting capabilities or trusting outputs for decisions the skill is not actually performing, masking unauthorized or irrelevant network actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to perform SHEIN category search and analysis, but the detected implementation reportedly resolves site information instead of category data and does not provide the advertised category identifiers, hierarchy, or filtering features. While this is not a classic exploit primitive by itself, such misrepresentation is dangerous because it can mislead operators into granting capabilities or trusting outputs for decisions the skill is not actually performing, masking unauthorized or irrelevant network actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "安装后直接用中文描述目标即可" explicitly directs users to interact in Chinese. Under the policy, language constraints should not be forced unless the skill offers a language choice, opt-in, or a clearly justified region-specific limitation, which is not documented here.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell commands, reads local reference files, and performs network-backed queries, but it does not declare any tool scope or permission boundaries. This creates an authority mismatch: a caller reviewing only the manifest cannot tell that the skill can execute commands and access external services, increasing the risk of unintended command execution or data access under overly broad runtime privileges.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction '输出中文业务结论' forces responses in Chinese for all users. This is a natural-language locale policy issue because the file does not offer a language choice or require Chinese only in a clearly documented region-specific context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a SHEIN category search and analytics skill, but this file implements a standalone login-state subsystem with multi-location storage resolution in user config, skill, and working directories. While network access to GeekBI is expected for search, persistent credential/state management is a broader behavior not disclosed by the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s user-facing description, argument help text, and error messages are all in Chinese, and the input help explicitly constrains the lookup to Chinese site names. This imposes a language/locale requirement without any opt-in or explanation that the tool is intentionally region-specific, which matches the policy’s locale-constraint concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains its module docstring and user-facing status/error messages entirely in Chinese, and there is no indication that users can opt into another language. The policy for this audit flags language or locale constraints when a skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest presents the skill as a category search/analysis capability, but this module also exposes a command-line interface for storage diagnostics and clearing auth state. That operational management surface is not reflected in the manifest's user-facing intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This Python file performs an authenticated HTTP request to a remote API, which may transmit user or system context such as authentication data, but the code provides no user-facing warning, confirmation, or explanatory comment/docstring about that network action. Under the code-file criteria, network calls should be disclosed unless the operation is clearly communicated elsewhere in the skill description, which is not evident in this file alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.