Back to skill

Security audit

极鲸云 Shein 评论搜索&分析

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims for SHEIN review lookup, but it stores GeekBI login tokens in multiple local plaintext locations, including the skill and current working directories.

Review before installing if you are uncomfortable with GeekBI login tokens being saved in multiple local places. Use it only in workspaces you do not share or publish, clear the GeekBI auth state when finished, and avoid running it from directories that may be archived, synced, or committed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:374
Finding

Bearer Access Token Is Replicated Across Multiple Plaintext Storage Locations

Content
View full analysis

Vulnerability Details

File Location: scripts/geekbi_auth.py:54-73, scripts/geekbi_auth.py:374-384, and scripts/geekbi_auth.py:637-652
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

The authentication module selects three separate locations for authentication state:

python
def _resolve_stores():
    candidates = (
        ResolvedStore(_user_config_state_path(), "user-config-directory"),
        ResolvedStore(_skill_state_path(), "skill-directory"),
        ResolvedStore(_workspace_state_path(), "working-directory"),
    )
    stores = []
    seen_paths = set()
    for store in candidates:
        path_key = os.path.normcase(os.fspath(store.path))
        if path_key in seen_paths:
            continue
        seen_paths.add(path_key)
        stores.append(store)
    return tuple(stores)

It then writes the same authentication state to every usable location:

python
def _write_state_files(stores, payload):
    normalized = _normalize_state(payload)
    errors = []
    written = 0
    for store in stores:
        try:
            _write_state_file(store, normalized)
            written += 1
        except OSError as error:
            errors.append(f"{store.kind}: {_storage_probe_reason(error)}")
    if written == 0:
        reason = ";".join(errors) or "登录状态目录不可用"
        raise OSError(reason)

The replicated state includes the bearer access token:

python
def save_token(latest):
    latest_server = latest["servers"].get(server_key)
    if not isinstance(latest_server, dict):
        return False, False
    latest_pending = latest_server.get("pending")
    if not isinstance(latest_pending, dict):
        return False, False
    if latest_pending.get("deviceCode") != pending.get("deviceCode"):
        return False, False
    _remove_access_token(latest_server)
    latest_server["accessToken"] = access_token
    latest_server["accessTokenExpiresAt"] = now + max(0, expires_in 
...[truncated 3207 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use one authentication store only. Store authentication state exclusively in the operating-system user configuration directory rather than mirroring it into the Skill and working directories.

  2. Prefer an operating-system credential manager. Store the bearer token in facilities such as Windows Credential Manager, macOS Keychain, or a Linux secret service. Keep only non-sensitive metadata in the JSON state file.

  3. Use fallback selection instead of replication. If the preferred credential store is unavailable, choose exactly one secure fallback location. Do not write the same token to every writable candidate.

  4. Migrate existing installations safely. On the first run after remediation:

    • Read the token from the highest-priority valid store.
    • Move it to the selected secure store.
    • Remove legacy copies from the Skill and workspace directories.
    • Report cleanup failures without printing token contents.
  5. Strengthen cleanup behavior. Make clear_auth_state() verify and report whether each known copy was deleted instead of silently ignoring deletion errors.

  6. Minimize token lifetime and privilege. Continue applying short expiration periods and ensure server-issued tokens are restricted to the minimum API scopes required for SHEIN review and site queries.

  7. Retain existing safeguards. Preserve atomic file replacement, restrictive POSIX permissions, token redaction, and .gitignore coverage as defense-in-depth measures, but do not rely on them as substitutes for eliminating redundant credential copies.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises product-review lookup by SHEIN goods ID, but the detected behavior instead performs site-list queries and site resolution using different inputs such as site name, UID, or domain. This is dangerous because a misrepresented skill can collect or process data outside user intent, and it undermines trust boundaries by exposing additional network functionality not obviously necessary for the requested task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description promises product-review lookup by SHEIN goods ID, but the detected behavior instead performs site-list queries and site resolution using different inputs such as site name, UID, or domain. This is dangerous because a misrepresented skill can collect or process data outside user intent, and it undermines trust boundaries by exposing additional network functionality not obviously necessary for the requested task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "安装后直接用中文描述目标即可" explicitly requires users to interact in Chinese. This is a natural-language locale constraint, and the file does not offer an opt-in choice or explain why Chinese is mandatory for this skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permissions while its documented workflow invokes file reads, shell scripts, and network-backed queries. That creates an authorization gap: the runtime may grant broader capabilities than users or reviewers expect, increasing the chance of unintended file access, command execution, or external requests through this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L40 explicitly requires using Simplified Chinese for outputs, with no indication that the user can choose another language or opt in to this locale constraint. This is a natural-language policy issue because it imposes a fixed language regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, short description, and default prompt are all written exclusively in Chinese, which indicates a fixed language/locale choice in the skill's natural-language interface. There is no indication that users can opt into this language or that the skill is intentionally limited to a Chinese-speaking region or audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring, exception messages, prompts, and CLI descriptions are written in Chinese throughout, which imposes a specific language on users without any opt-in or alternative locale support. Under the policy, forcing a language or locale without user choice is a natural-language policy violation unless the scope is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for querying and analyzing SHEIN product reviews based on a product ID and says conclusions are based only on returned reviews. This file implements a persistent authentication subsystem with local state storage, token lifecycle management, and login challenge handling, which is broader than the user-facing scope described for review retrieval and analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill purpose is to search and analyze product reviews for a specified SHEIN item ID, but this file adds standalone capabilities to inspect storage paths and delete authentication state across multiple local directories. Those administrative local-state management features are not an obvious requirement of review analysis itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language strings, including the module docstring, argument description, validation errors, and CLI description, are exclusively in Chinese. Under the policy rule, forcing a specific language without opt-in or justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

技能清单描述将该技能限定为基于明确商品 ID 查询并分析 SHEIN 商品评论,但此文件实现的是查询 SHEIN 站点列表并按站点名称、UID 或域名解析站点。该行为既不处理商品 ID,也不处理评论内容,属于与清单声明不一致的额外功能。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the docstring, CLI description, argument help, and error messages require Chinese usage and specifically ask for Chinese site names. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module is presented as GeekBI agent authentication support, but the user config path persists state under "temu-research-skill", which contradicts the manifested identity and purpose of this SHEIN review skill. This suggests copied intent/documentation from another skill and makes the actual target of the stored auth state ambiguous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The clear_auth_state function deletes the persisted login state files across all resolved stores, but the function itself contains no confirmation prompt, warning comment, or user-facing disclosure about this destructive action. Although the CLI exposes a "clear" command, the implementation gives no explicit warning that it will remove saved authentication state from multiple locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

Importing and using authenticated_json_request implies the script may read authentication material to call the remote API, but the file does not warn users that credentials or sensitive environment state could be used. For code-file warning criteria, access to credentials should have some visible disclosure unless already documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends user-supplied search parameters to an external API via authenticated_json_request, but the file provides no comment, docstring detail, or runtime notice explaining that data will be transmitted off-host. Although network access is central to the script's purpose, the current file gives only a generic description and does not explicitly disclose the outbound data transfer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.