Back to skill

Security audit

极鲸云 Shein 商品搜索&分析

Security checks for vulnerabilities and agentic risk

Overview

This SHEIN research skill mostly matches its stated purpose, but it needs review because it stores GeekBI login tokens in multiple local locations and trusts server-provided login links without validating them.

Review this skill before installing if you use a GeekBI account. Use only the official GeekBI endpoint, verify any login link before opening it, avoid sharing workspaces after login, and remove .geekbi/agent-auth.json files from the skill or working directory if they appear.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:58
Finding

Bearer authentication state is mirrored into project and working directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:669
Finding

Server-provided authentication links are presented without trusted-origin validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向 SHEIN 商品搜索与选品分析的业务技能,核心能力应包括商品数据查询、按关键词/类目/价格/销量等筛选,以及榜单、趋势、竞争分析等。实际代码却是一个通用认证模块 geekbi_auth.py,主要职责是极鲸云登录状态管理和认证请求封装。它会访问认证接口 /api/v1/agent/auth/token,维护 accessToken/pending/deviceCode/jumpUrl,读写本地 agent-auth.json,并提供 storage-status/clear 命令行功能。代码中没有任何与 SHEIN 商品、搜索条件、类目、销量、价格分析、榜单生成或选品判断相关的实现。因此这不是简单的支撑细节泄露,而是该代码块的实际功能与声明的业务用途明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心行为与声明中的“搜索/筛选 SHEIN 商品数据”部分一致:它允许传入关键词、类目 ID、站点、托管模式、销量/销售额/价格/供货价/评分/上架时间等过滤条件,并调用极鲸云的 SHEIN 商品 AI 搜索接口获取真实数据。然而,声明还强调了一系列更高层的分析与判断能力,例如热销榜、新品榜、低竞争商品识别、候选商品比较、价格带分析、销量趋势、竞争强度和选品机会判断。当前代码中没有任何对返回结果进行分析、排序汇总、候选对比、趋势计算或结论生成的逻辑,只是参数校验后发起请求并输出响应。因此,声明显著高于代码实际能力,构成描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向 SHEIN 商品搜索、筛选和选品分析的技能,核心对象应是商品数据及其分析结论。但实际代码的唯一功能是查询 SHEIN 站点列表接口,并根据用户提供的国家/地区/站点名称、UID 或域名来解析站点信息。它不处理商品、不做筛选、不做榜单、不做趋势分析,也不产生任何选品判断。因此代码的主要目的与声明用途明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction "安装后直接用中文描述目标即可" imposes a specific language for using the skill. Under the policy, forcing a language or locale without user opt-in is a natural-language policy violation unless a justified region-specific constraint is documented, which is not present here.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes local file reads, network access, and shell commands but does not declare an explicit tool scope or permissions boundary. That increases the risk of over-privileged execution, making it harder for a host platform to constrain what the skill may access if the referenced scripts or docs are modified or behave unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, short description, and default prompt are entirely in Chinese, which implies a fixed language/locale choice in user-facing skill metadata. The file does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L47 明确说明网页文案中的“销量不超过 1000”并不是实际请求条件,且不会自动补充 soldMax。这里不是文档遗漏,而是明确指出外部宣称的筛选语义与真实执行条件相矛盾,可能让用户误以为结果已按销量上限过滤。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, beginning with the module docstring and continuing throughout prompts and error messages. Under the policy rule for language/locale, this is a violation because the skill enforces a specific language without user opt-in and without any documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill for searching and analyzing SHEIN product data based on GeekBI responses, but this file implements persistent authentication state across user config, skill, and working directories. While network access to GeekBI is expected, maintaining mirrored local login state and session lifecycle management is a broader behavior not disclosed in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file contains user-facing natural-language strings that require or assume Chinese usage, such as the docstring, argument description, and error messages stating the input must be a Chinese site name, site UID, or domain. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require the skill to '默认使用简体中文' and to use Chinese business terms for users, which imposes a language preference without offering the user a choice. The policy for natural-language violations applies to all file types and flags forced language or locale behavior unless the user is given an opt-in or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

L03 直接写明“文案与代码不一致时以代码为准”,这表明该预设文档所表达的意图不能完全代表实际行为,存在主动披露的文档/实现不一致。虽然这更像元说明而非具体单条功能矛盾,但它确实揭示了注释性文档与实际代码之间存在已知偏差。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L86 直接说明网页文案曾写“近 1 个月”,而实际请求是近 3 个月。这个时间窗口差异会实质影响结果范围,因此属于文档意图与实际行为的明确冲突。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames the skill as a SHEIN product search and selection tool, but this module also provides command-line administrative functions for checking storage status and clearing login state. These operational capabilities are not reflected in the user-facing description of the skill's purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language strings for the module docstring, CLI description, help text, and error messages exclusively in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.