Back to skill

Security audit

极鲸云 Shein 图搜同款&图片搜索分析

Security checks for vulnerabilities and agentic risk

Overview

This SHEIN image-search skill is mostly purpose-aligned, but it stores authentication tokens in multiple local locations and accepts broad image and endpoint inputs that deserve review before installation.

Review this skill before installing if you work in sensitive repositories or private networks. Only provide images you intend to send to GeekBI, avoid internal/private image URLs, do not use untrusted --base-url values, and check for .geekbi/agent-auth.json copies in the skill and working directories after authentication.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shein_image_search.py:276
Finding

Unrestricted Remote Image Retrieval Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:60
Finding

Authentication Tokens Are Replicated into Skill and Working Directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shein_image_search.py:345
Finding

Unvalidated API Base URL and Server-Supplied Action URLs Create Credential and Phishing Risks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad image-ingestion, visual search, and product-filtering functionality, but the detected implementation reportedly does not perform those actions and instead mainly queries/parse SHEIN site lists. This kind of capability mismatch can cause agents or users to trust outputs as if they were derived from image search when they are not, leading to deceptive automation, incorrect decisions, and unsafe downstream handling of inputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims broad image-ingestion, visual search, and product-filtering functionality, but the detected implementation reportedly does not perform those actions and instead mainly queries/parse SHEIN site lists. This kind of capability mismatch can cause agents or users to trust outputs as if they were derived from image search when they are not, leading to deceptive automation, incorrect decisions, and unsafe downstream handling of inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says "安装后直接用中文描述目标即可", which directs users to interact in Chinese only. This is a natural-language locale constraint, and the file does not offer an opt-in choice or explain that the skill is region-specific enough to justify the restriction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructions direct the agent to use file reads, shell commands, and network access, but the skill declares no explicit tool scope or permission boundary. That creates an authorization gap: a caller or orchestrator may not realize the skill can access local files, invoke scripts, and transmit image or session-derived data to external services, increasing the chance of overbroad execution and unintended data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L03 将触发场景表述为“图片对应商品表现”“根据商品图片判断选品机会”等宽泛业务表达,且与更通用的“上传图片找同款”“截图搜款”并列,没有给出明确的触发边界或排除条件。这类描述容易与日常电商分析、商品评估类对话重叠,导致技能在不需要 SHEIN 图搜时被意外调用。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L15 明确要求“面向用户使用中文业务名称”,这构成了对输出语言/本地化的强制限制,但文档中未说明仅适用于中文用户场景,也未提供用户选择其他语言的选项。根据语言/地区策略,未经用户选择即强制特定语言属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L148 instructs that only the Chinese server-provided message should be shown to the user, which imposes a specific language choice regardless of the user's preferred locale. This is a natural-language policy issue because the file does not offer any language choice or opt-in for non-Chinese users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This is a natural-language policy issue because the file forces a specific language for its interface and error messages. The code contains Chinese-only descriptions and messages, and there is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This module injects an X-GeekBI-Skill-Version header using a hard-coded skill version, but the surrounding state path naming suggests the implementation may belong to or be shared with a different skill lineage. In combination with the manifest's SHEIN-specific purpose, this creates a credible description-to-code mismatch about which skill is actually being authenticated and tracked.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a SHEIN image-search skill, but this auth helper persists state in a config path ending with "temu-research-skill". That indicates the code is reusing or targeting another skill's state namespace rather than state clearly scoped to the declared SHEIN image-search skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argparse description and subcommand help strings are user-facing natural-language content, and they are fixed to Chinese. Because the file does not provide a language choice or explain that the tool is region- or locale-specific, this violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script accepts image data from local files, stdin, Base64/Data URI, or arbitrary remote URLs and then uploads the resulting bytes to an external API endpoint. Although this is the stated business purpose of the skill, the code provides no explicit consent prompt, destination disclosure, or restriction against sensitive local files being supplied accidentally, which creates a real data-exfiltration risk in an agent setting where users may not realize content is transmitted off-host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language interface is entirely Chinese: the module docstring, CLI description, help text, and error messages require or assume Chinese input such as '中文站点名'. This creates a locale-policy issue because the skill enforces a specific language without any opt-in or alternative locale path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.