T09 · Insecure Skill Coding Practices
- Location
scripts/geekbi_auth.py:69- Finding
Bearer Tokens Are Mirrored into Skill and Working Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it stores login tokens in multiple local places including the current workspace, which users should review before installing.
Install only if you are comfortable with this skill using your GeekBI session for SHEIN data queries and storing login state locally. Before using it in shared, synced, or build-artifact workspaces, consider clearing auth state after use or avoiding workspaces where .geekbi/agent-auth.json could be collected.
scripts/geekbi_auth.py:69Bearer Tokens Are Mirrored into Skill and Working Directories
requirements.txt:1Dependency Installation Is Not Reproducibly Pinned or Integrity-Verified
A second behavior-mismatch finding indicates the declared shop-search functionality is not what is actually executed; instead, the skill appears to call a site-list endpoint and return site parsing results rather than shop data. Such deceptive or inaccurate capability claims undermine trust boundaries and can conceal unexpected data access, authentication flows, or side effects from operators who believe they are enabling a narrowly scoped business lookup tool.
A second behavior-mismatch finding indicates the declared shop-search functionality is not what is actually executed; instead, the skill appears to call a site-list endpoint and return site parsing results rather than shop data. Such deceptive or inaccurate capability claims undermine trust boundaries and can conceal unexpected data access, authentication flows, or side effects from operators who believe they are enabling a narrowly scoped business lookup tool.
Referenced artifact was not completely inspected
- 先直接运行店铺搜索脚本。脚本通过 `scripts/geekbi_auth.py` 优先读取所有极鲸云 Skills 共用的系统用户配置登录态;已有有效登录态时不得再次要求登录。
The phrase "安装后直接用中文描述目标即可" directs use in a specific language and does not indicate that other languages are supported or optional. Under the policy, forcing a language without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.
The skill declares no explicit tool scope or permission boundaries while instructing use of file reads, shell execution, package installation, and network-backed scripts. In an agent environment, missing least-privilege constraints can allow broader-than-expected execution and increases the blast radius if the skill or referenced scripts are modified or abused.
The instruction "输出中文业务结论" mandates a specific language for responses. This is a natural-language policy concern because the file does not offer the user a language choice or indicate opt-in for Chinese-only output.
The instruction requires using the server's Chinese msg verbatim, which forces a specific language in user-facing output. The file does not offer a language choice or indicate that Chinese-only output is a justified, region-specific constraint.
The file’s natural-language strings, including the module docstring, error messages, and CLI description/help text, are entirely in Chinese with no indication that the skill is region-specific or that users can choose another language. This creates a locale policy concern because the skill imposes a specific language on all users rather than offering opt-in or documenting a justified restriction.
The module docstring states the tool queries and resolves SHEIN sites using Chinese-language descriptions, and later argument/help text also requires Chinese site names. This is a natural-language locale constraint presented as mandatory behavior, with no opt-in or alternative language support documented.
The help text for --country says the input must be a Chinese site name, site UID, or domain, which imposes a language-specific requirement. Because the file does not explain that this is a justified region-specific tool or offer another locale option, it conflicts with the language/locale policy guidance.
The manifest describes a skill for searching and analyzing SHEIN shops with filtering and ranking, but this file implements a reusable authentication subsystem: probing storage locations, persisting tokens/device codes, locking files, and clearing auth state. While network access to the GeekBI service is expected for search, local credential state management is an additional behavior not reflected in the manifest description.
The manifest focuses on end-user shop search and analytics capabilities, but this file also exposes operational commands to inspect storage health and delete authentication state. These are support functions rather than search features, and they are not mentioned in the stated skill purpose.
No suspicious patterns detected.