T09 · Insecure Skill Coding Practices
- Location
scripts/shein_image_search.py:276- Finding
Unrestricted Remote Image Retrieval Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This SHEIN image-search skill is mostly purpose-aligned, but it stores authentication tokens in multiple local locations and accepts broad image and endpoint inputs that deserve review before installation.
Review this skill before installing if you work in sensitive repositories or private networks. Only provide images you intend to send to GeekBI, avoid internal/private image URLs, do not use untrusted --base-url values, and check for .geekbi/agent-auth.json copies in the skill and working directories after authentication.
scripts/shein_image_search.py:276Unrestricted Remote Image Retrieval Enables Server-Side Request Forgery
scripts/geekbi_auth.py:60Authentication Tokens Are Replicated into Skill and Working Directories
scripts/shein_image_search.py:345Unvalidated API Base URL and Server-Supplied Action URLs Create Credential and Phishing Risks
The skill claims broad image-ingestion, visual search, and product-filtering functionality, but the detected implementation reportedly does not perform those actions and instead mainly queries/parse SHEIN site lists. This kind of capability mismatch can cause agents or users to trust outputs as if they were derived from image search when they are not, leading to deceptive automation, incorrect decisions, and unsafe downstream handling of inputs.
The skill claims broad image-ingestion, visual search, and product-filtering functionality, but the detected implementation reportedly does not perform those actions and instead mainly queries/parse SHEIN site lists. This kind of capability mismatch can cause agents or users to trust outputs as if they were derived from image search when they are not, leading to deceptive automation, incorrect decisions, and unsafe downstream handling of inputs.
The README says "安装后直接用中文描述目标即可", which directs users to interact in Chinese only. This is a natural-language locale constraint, and the file does not offer an opt-in choice or explain that the skill is region-specific enough to justify the restriction.
The skill instructions direct the agent to use file reads, shell commands, and network access, but the skill declares no explicit tool scope or permission boundary. That creates an authorization gap: a caller or orchestrator may not realize the skill can access local files, invoke scripts, and transmit image or session-derived data to external services, increasing the chance of overbroad execution and unintended data exposure.
L03 将触发场景表述为“图片对应商品表现”“根据商品图片判断选品机会”等宽泛业务表达,且与更通用的“上传图片找同款”“截图搜款”并列,没有给出明确的触发边界或排除条件。这类描述容易与日常电商分析、商品评估类对话重叠,导致技能在不需要 SHEIN 图搜时被意外调用。
L15 明确要求“面向用户使用中文业务名称”,这构成了对输出语言/本地化的强制限制,但文档中未说明仅适用于中文用户场景,也未提供用户选择其他语言的选项。根据语言/地区策略,未经用户选择即强制特定语言属于自然语言政策风险。
Line L148 instructs that only the Chinese server-provided message should be shown to the user, which imposes a specific language choice regardless of the user's preferred locale. This is a natural-language policy issue because the file does not offer any language choice or opt-in for non-Chinese users.
This is a natural-language policy issue because the file forces a specific language for its interface and error messages. The code contains Chinese-only descriptions and messages, and there is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-speaking context.
This module injects an X-GeekBI-Skill-Version header using a hard-coded skill version, but the surrounding state path naming suggests the implementation may belong to or be shared with a different skill lineage. In combination with the manifest's SHEIN-specific purpose, this creates a credible description-to-code mismatch about which skill is actually being authenticated and tracked.
The manifest describes a SHEIN image-search skill, but this auth helper persists state in a config path ending with "temu-research-skill". That indicates the code is reusing or targeting another skill's state namespace rather than state clearly scoped to the declared SHEIN image-search skill behavior.
The argparse description and subcommand help strings are user-facing natural-language content, and they are fixed to Chinese. Because the file does not provide a language choice or explain that the tool is region- or locale-specific, this violates the language/locale policy criteria.
The script accepts image data from local files, stdin, Base64/Data URI, or arbitrary remote URLs and then uploads the resulting bytes to an external API endpoint. Although this is the stated business purpose of the skill, the code provides no explicit consent prompt, destination disclosure, or restriction against sensitive local files being supplied accidentally, which creates a real data-exfiltration risk in an agent setting where users may not realize content is transmitted off-host.
The natural-language interface is entirely Chinese: the module docstring, CLI description, help text, and error messages require or assume Chinese input such as '中文站点名'. This creates a locale-policy issue because the skill enforces a specific language without any opt-in or alternative locale path.
No suspicious patterns detected.