Back to skill

Security audit

极鲸云 Shein 店铺搜索&分析

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it stores login tokens in multiple local places including the current workspace, which users should review before installing.

Install only if you are comfortable with this skill using your GeekBI session for SHEIN data queries and storing login state locally. Before using it in shared, synced, or build-artifact workspaces, consider clearing auth state after use or avoiding workspaces where .geekbi/agent-auth.json could be collected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:69
Finding

Bearer Tokens Are Mirrored into Skill and Working Directories

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Installation Is Not Reproducibly Pinned or Integrity-Verified

Content
View full analysis
=4.0,<5.0 ``` `SKILL.md`: ```text If the environment has not installed dependencies, run `python3 -m pip install -r requirements.txt` before executing the query script. ``` The quoted `SKILL.md` instruction is an English translation of the audited instruction; the executable command is reproduced exactly. ### Technical Analysis The dependency specification permits any package release in the `platformdirs` 4.x series, including releases published after this Skill was reviewed. The installation instruction directs the Agent to invoke pip without an exact version, a lock file, integrity hashes, or an explicitly trusted package index. This is a supply-chain hardening weakness. There is no evidence in the audited project that the current `platformdirs` package is malicious. Exploitation depends on compromise of the package publisher, configured package index, network/package-resolution environment, or a future compatible release. Python package installation can execute build backend or installation-related code in the context of the user running pip. Consequently, allowing an unreviewed future version means the code ultimately installed may differ from the code considered during this audit. ### Attack Path 1. The Skill runs in an environment where `platformdirs` is not already installed. 2. The Agent follows `SKILL.md` and executes `python3 -m pip install -r requirements.txt`. 3. Pip resolves any available version satisfying `>=4.0,<5.0` from the configured package index. 4. A compromised publisher, malicious index, poisoned resolver configuration, or affected future release supplies hostile package content. 5. Pip downloads and installs that content, potentially executing package build or installation code with the ...[truncated 692 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second behavior-mismatch finding indicates the declared shop-search functionality is not what is actually executed; instead, the skill appears to call a site-list endpoint and return site parsing results rather than shop data. Such deceptive or inaccurate capability claims undermine trust boundaries and can conceal unexpected data access, authentication flows, or side effects from operators who believe they are enabling a narrowly scoped business lookup tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second behavior-mismatch finding indicates the declared shop-search functionality is not what is actually executed; instead, the skill appears to call a site-list endpoint and return site parsing results rather than shop data. Such deceptive or inaccurate capability claims undermine trust boundaries and can conceal unexpected data access, authentication flows, or side effects from operators who believe they are enabling a narrowly scoped business lookup tool.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- 先直接运行店铺搜索脚本。脚本通过 `scripts/geekbi_auth.py` 优先读取所有极鲸云 Skills 共用的系统用户配置登录态;已有有效登录态时不得再次要求登录。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase "安装后直接用中文描述目标即可" directs use in a specific language and does not indicate that other languages are supported or optional. Under the policy, forcing a language without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope or permission boundaries while instructing use of file reads, shell execution, package installation, and network-backed scripts. In an agent environment, missing least-privilege constraints can allow broader-than-expected execution and increases the blast radius if the skill or referenced scripts are modified or abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction "输出中文业务结论" mandates a specific language for responses. This is a natural-language policy concern because the file does not offer the user a language choice or indicate opt-in for Chinese-only output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction requires using the server's Chinese msg verbatim, which forces a specific language in user-facing output. The file does not offer a language choice or indicate that Chinese-only output is a justified, region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s natural-language strings, including the module docstring, error messages, and CLI description/help text, are entirely in Chinese with no indication that the skill is region-specific or that users can choose another language. This creates a locale policy concern because the skill imposes a specific language on all users rather than offering opt-in or documenting a justified restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring states the tool queries and resolves SHEIN sites using Chinese-language descriptions, and later argument/help text also requires Chinese site names. This is a natural-language locale constraint presented as mandatory behavior, with no opt-in or alternative language support documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The help text for --country says the input must be a Chinese site name, site UID, or domain, which imposes a language-specific requirement. Because the file does not explain that this is a justified region-specific tool or offer another locale option, it conflicts with the language/locale policy guidance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for searching and analyzing SHEIN shops with filtering and ranking, but this file implements a reusable authentication subsystem: probing storage locations, persisting tokens/device codes, locking files, and clearing auth state. While network access to the GeekBI service is expected for search, local credential state management is an additional behavior not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest focuses on end-user shop search and analytics capabilities, but this file also exposes operational commands to inspect storage health and delete authentication state. These are support functions rather than search features, and they are not mentioned in the stated skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.