Back to skill

Security audit

极鲸云 Shein 关键词搜索&分析

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real GeekBI SHEIN keyword-search skill, but it stores authentication tokens in multiple local locations and exposes an unscoped API destination override.

Review before installing if you use shared workspaces or handle sensitive GeekBI account data. The skill will persist GeekBI login state locally, including in the current workspace when writable, and its scripts contain a base URL override that should only be used with the official GeekBI HTTPS endpoint unless you intentionally trust another server.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:63
Finding

Bearer Token State Is Unnecessarily Replicated Across Multiple Storage Locations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:703
Finding

Unrestricted Base URL Allows Arbitrary or Plaintext Authentication and API Destinations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims to perform keyword analysis, but the behavior includes shared login-state reuse, pause/resume authentication handling, token persistence, and access to local state storage. This mismatch can conceal sensitive credential handling and local file interactions from reviewers and users, making it easier for over-privileged or risky behavior to bypass scrutiny.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to perform keyword analysis, but the behavior includes shared login-state reuse, pause/resume authentication handling, token persistence, and access to local state storage. This mismatch can conceal sensitive credential handling and local file interactions from reviewers and users, making it easier for over-privileged or risky behavior to bypass scrutiny.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction "安装后直接用中文描述目标即可" tells users to interact in Chinese and does not provide an opt-in, alternative language option, or region-specific justification. This is a natural-language locale policy concern because it imposes a specific language on all users of the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares no explicit tool scope while its documented behavior invokes file reads, shell scripts, and networked API access. Missing least-privilege boundaries increases the blast radius if the skill is mis-triggered, modified, or abused, because it can access local state and execute commands without an auditable declaration of what is permitted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description lists many broad user intents such as searching keywords, checking hot-selling words, blue-ocean words, new words, and analyzing trends, but it does not define specific trigger phrases or exclusion conditions. In a manifest file, this kind of expansive natural-language activation scope can cause unintended invocation for general e-commerce analysis requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring, CLI description, help text, and runtime error/action messages are written entirely in Chinese, which imposes a specific language on users without opt-in. The policy allows locale constraints only when documented and justified or when the user is offered a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames the skill as using GeekBI data to search and analyze SHEIN keywords and to form conclusions from returned analytics data. In contrast, this module's primary behavior is managing authentication state on disk, handling device-code login challenges, clearing auth files, and wrapping authenticated HTTP requests, which is a broader auth-management subsystem not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The clear_auth_state function unlinks authentication state files from multiple locations, which is a destructive file operation affecting the user's saved login state. There is no confirmation prompt and no user-facing disclosure near the deletion logic explaining that local auth data will be removed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction says to use Simplified Chinese by default, which is a language policy constraint expressed in natural language. Because the file does not mention user choice or opt-in for language selection, this is a locale/language policy violation under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The display name, description, and default prompt are all written in Chinese, but the file does not indicate that the skill is region-specific or that language is user-selectable. Under the policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest identifies this skill as 'geekbi-shein-keyword-search-skill', but the code stores auth state under a 'temu-research-skill' path. This is not merely incomplete documentation; it actively points to a different skill context, suggesting copied or stale intent documentation/code that contradicts the current skill identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This Python file makes an authenticated HTTP request to an external API, which transmits user-supplied query parameters and potentially associated authentication context. While the module docstring states the script calls the SHEIN keyword search interface, there is no user-facing warning, prompt, or runtime notice near execution explaining that data will be sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language strings exclusively in Chinese, including the module docstring, argument descriptions, and error messages. Under the policy rule for language/locale, this effectively forces a specific language without any user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.