Back to skill

Security audit

极鲸云 Shein 数据分析与市场调研

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its SHEIN research purpose, but it needs review because it stores login tokens in several local plaintext files and can fetch any image URL from the user's environment before uploading it to GeekBI.

Install only if you trust GeekBI with the SHEIN queries, uploaded images, and account token used by this skill. Avoid giving it internal, private, or sensitive image URLs; prefer local files you intend to upload. Review and, if possible, reduce the auth-state storage locations before use, and clear .geekbi auth files after testing or in shared workspaces.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shein_image_search.py:122
Finding

Unrestricted Remote Image Fetching Enables Server-Side Request Forgery and Data Relay

Content
View full analysis

Vulnerability Details

File Location: scripts/shein_image_search.py:122-125, with the vulnerable input routing at lines 158-166 and external upload at lines 213-224
Vulnerability Type: Server-Side Request Forgery (SSRF) and unintended data relay
Risk Level: Medium

Vulnerable Code

python
def _read_remote_image(source, timeout):
    request = Request(source, headers={"User-Agent": "GeekBI-SHEIN-Research-Skill"})
    with urlopen(request, timeout=timeout) as response:
        data = _read_limited(response)
        content_type = _validate_image(data, response.headers.get_content_type())
        path_name = Path(unquote(urlparse(response.geturl()).path)).name
        filename = path_name or "image" + _extension(content_type)
        return data, content_type, filename

The input dispatcher permits any HTTP or HTTPS URL:

python
parsed = urlparse(source)
if parsed.scheme in {"http", "https"}:
    return _read_remote_image(source, timeout)
if parsed.scheme not in {"", "file"}:
    raise ValueError("图片地址只支持本地文件、file、http 或 https")
return _read_local_image(source)

Successfully fetched content is uploaded to the configured GeekBI endpoint:

python
data, content_type, filename = read_image_source(args.image, args.timeout)
body, multipart_content_type = build_multipart(data, content_type, filename)
payload = authenticated_json_request(
    build_url(args.base_url, params),
    args.base_url,
    args.timeout,
    method="POST",
    body=body,
    headers={"Content-Type": multipart_content_type},
)

Technical Analysis

The --image option accepts an arbitrary HTTP or HTTPS URL and passes it directly to urllib.request.urlopen. The implementation does not:

  • Reject loopback, private, link-local, reserved, multicast, or cloud-metadata IP ranges.
  • Resolve and validate the destination address before connecting.
  • Revalidate destination addresses ...[truncated 2350 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer local user-provided files and disable remote URL fetching unless it is strictly necessary.
  2. If remote fetching is required, maintain an explicit allowlist of approved public image hosts.
  3. Resolve the hostname before connecting and reject every address in loopback, private, link-local, multicast, unspecified, reserved, and documentation ranges for both IPv4 and IPv6.
  4. Explicitly block cloud metadata destinations, including link-local metadata addresses and provider-specific metadata hostnames.
  5. Disable automatic redirects or implement a small redirect limit and repeat full scheme, hostname, DNS, and IP validation for every redirect target.
  6. Protect against DNS rebinding by connecting only to the validated resolved address while preserving safe TLS hostname verification.
  7. Permit HTTPS only unless a documented use case requires HTTP.
  8. Apply outbound network controls at the container or host level so the Skill cannot reach internal networks or metadata services.
  9. Obtain explicit user confirmation before transmitting a fetched image to GeekBI, especially when the source is not a user-uploaded local file.
  10. Add tests covering loopback addresses, RFC 1918 ranges, IPv6 local addresses, metadata endpoints, redirects to private hosts, alternate numeric IP formats, and DNS rebinding scenarios.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/geekbi_auth.py:61
Finding

Bearer Tokens Are Stored in Plaintext and Mirrored Across Multiple Directories

Content
View full analysis

Vulnerability Details

File Location: scripts/geekbi_auth.py:61-83, with state mirroring at lines 378-395 and token persistence at lines 631-650
Vulnerability Type: Excessive plaintext credential persistence
Risk Level: Low

Vulnerable Code

The implementation defines three authentication-state destinations:

python
def _user_config_state_path():
    return _absolute_path(
        user_config_path("GeekBI", appauthor=False, ensure_exists=True)
        / "temu-research-skill"
        / AUTH_FILE_NAME
    )


def _skill_state_path():
    return _absolute_path(Path(__file__).parent.parent / AUTH_STATE_DIR / AUTH_FILE_NAME)


def _workspace_state_path():
    return _absolute_path(Path(os.getcwd()) / AUTH_STATE_DIR / AUTH_FILE_NAME)


def _resolve_stores():
    candidates = (
        ResolvedStore(_user_config_state_path(), "user-config-directory"),
        ResolvedStore(_skill_state_path(), "skill-directory"),
        ResolvedStore(_workspace_state_path(), "working-directory"),
    )

State is written to every usable store rather than one selected secure location:

python
def _write_state_files(stores, payload):
    normalized = _normalize_state(payload)
    errors = []
    written = 0
    for store in stores:
        try:
            _write_state_file(store, normalized)
            written += 1
        except OSError as error:
            errors.append(f"{store.kind}: {_storage_probe_reason(error)}")
    if written == 0:
        reason = ";".join(errors) or "登录状态目录不可用"
        raise OSError(reason)

The access token is included directly in the JSON state:

python
_remove_access_token(latest_server)
latest_server["accessToken"] = access_token
latest_server["accessTokenExpiresAt"] = now + max(0, expires_in - 30)
latest_server.pop("pending", None)

Technical Analysis

The bearer token is persisted as plaintext JSON and mirrored t ...[truncated 2621 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store authentication state in exactly one dedicated user configuration location named for this Skill, such as geekbi-shein-research-skill.
  2. Remove authentication-state persistence from the installed Skill directory and current working directory.
  3. Use the operating system credential manager or keychain for bearer tokens where available.
  4. If file storage is unavoidable, store only non-secret metadata in JSON and protect the token with an OS-backed encryption mechanism.
  5. Treat failures to enforce restrictive permissions as errors rather than silently continuing.
  6. On supported POSIX systems, verify directory ownership and reject symlinks or files owned by unexpected users before reading or writing state.
  7. On Windows, configure an access control list limited to the current user instead of relying on POSIX-only permission functions.
  8. Implement a secure migration from the legacy temu-research-skill path: import only after validating ownership and permissions, then securely remove the old state.
  9. Ensure logout or clear removes all historical copies and revokes the server-side token when the API supports revocation.
  10. Document token retention, expiration, storage location, and cleanup behavior for users and administrators.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description says it performs SHEIN research and analysis, but the detected behavior includes undeclared authentication handling, local auth-state persistence/cleanup, and tokenized request wrapping. Hidden auth flows and credential/state management are security-relevant behaviors; when they are not disclosed, they can surprise operators, bypass expected review, and increase the risk of credential leakage, misuse, or unsafe state retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description says it performs SHEIN research and analysis, but the detected behavior includes undeclared authentication handling, local auth-state persistence/cleanup, and tokenized request wrapping. Hidden auth flows and credential/state management are security-relevant behaviors; when they are not disclosed, they can surprise operators, bypass expected review, and increase the risk of credential leakage, misuse, or unsafe state retention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage guidance says '安装后直接用中文描述目标即可', which sets Chinese as the required interaction language. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill references local file reads, shell scripts, and network-backed workflows but does not declare an explicit tool or permission scope. That creates an authorization transparency gap: reviewers and users cannot tell what the skill is allowed to access, increasing the chance of over-broad execution or unexpected data access if the runtime grants default capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L12 states '默认使用简体中文', which imposes a language choice as the default behavior. The policy allows locale or language constraints only when the user is given a choice or the restriction is clearly justified; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, short description, and default prompt are all written only in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L07 instructs the skill to present results to users in Chinese and avoid repeating English parameters or raw responses. This imposes a specific language on all users without offering a choice or documenting a justified locale restriction, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says to use the server's Chinese msg verbatim and not rewrite its meaning. This imposes a specific language on user-facing output without offering a language choice or documenting a justified locale restriction, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing docstrings, error messages, prompts, and CLI descriptions entirely in Chinese, such as the module docstring, exception messages, and command help text. Because the skill does not appear to offer any language selection or document a justified locale restriction, it violates the language/locale policy criterion for natural-language policy violations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

模块文档与清单都表明这是 SHEIN research skill 的认证封装,但用户配置目录路径被硬编码为 "temu-research-skill"。这会让代码实际把当前技能的登录状态写入另一个技能名下的目录,属于代码标识意图与实际技能身份不一致的主动矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language text such as the module docstring, argument description, help text, and error messages exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script accepts an http/https image URL, fetches the image, and then uploads the image contents to the GeekBI API, but it does not provide any explicit user-facing notice that third-party image data will be transmitted over the network. In a research skill that may process user-supplied or externally hosted images, this creates a real privacy and data-handling risk: users may unintentionally cause sensitive or proprietary images, or requests to internal-looking URLs, to be sent to remote services without clear consent or visibility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains multiple natural-language strings in Chinese, including the module docstring, argument descriptions, and validation error messages. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring, CLI description, help text, and error messages all specify or imply Chinese-only interaction, such as requiring a Chinese site name and returning Chinese-language messages. This is a natural-language locale policy concern because the file does not offer an opt-in language choice or explain why the restriction is necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

该文件标题与全文说明均仅使用中文,且未说明是否支持其他语言或允许用户选择语言。根据规则,若技能在自然语言层面隐含强制特定语言而无用户选择或正当说明,可构成语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description and user-facing messages in this file are written in Chinese, but the skill does not offer any language selection or explain that it is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when users are not given an opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.