Back to skill

Security audit

极鲸云 Temu 类目搜索/品类搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Temu category-search purpose, but it deserves review because it stores login tokens in multiple local folders and leaves some network/link destinations insufficiently constrained.

Review before installing. Use this skill only if you are comfortable logging into GeekBI, storing a reusable GeekBI token locally, and receiving vendor-provided links in results. Prefer running it in an isolated workspace, avoid passing custom --base-url values, and remove .geekbi/agent-auth.json copies when finished.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/Temu类目搜索.md:27
Finding

Mandatory Rendering of Unvalidated Server-Controlled Links

Content
View full analysis
)`;这条规则适用于表格、列表、排名、候选清单和正文,不因用户未主动要求链接或要求简洁结果而省略。 ``` Equivalent mandatory behavior also appears at: - `references/Temu类目搜索.md`, lines 42-46 - `references/Temu类目搜索接口.md`, lines 109-112 - `SKILL.md`, lines 14-17 ### Technical Analysis The Skill instructs the agent to embed every non-empty server-provided `linkUrl` in its response, even when the user did not request links or explicitly requested concise output. No URL validation is performed before the value is presented as a clickable Markdown link. The response contract only states that `linkUrl` is expected to point to a GeekBI page. It does not enforce: - An `https` scheme. - An approved GeekBI hostname. - Rejection of credentials embedded in a URL. - Rejection of look-alike or internationalized domain names. - Rejection of dangerous or unsupported URI schemes. - Removal of tracking parameters. - Respect for a user's request not to receive promotional links. This behavior changes the agent's response policy and delegates control over rendered destinations to the remote API. ### Attack Path 1. The agent invokes the category-search API as directed by the Skill. 2. The API, an upstream proxy, or a compromised service returns category data containing an attacker-controlled `linkUrl`. 3. The Skill instructions require the agent to embed the URL in every displayed category name or path. 4. The resulting answer presents the malicious destination as a normal category-detail link. 5. A user follows the link and is redirected to a phishing page, credential-harvesting page, malware delivery page, or deceptive payment page ...[truncated 525 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/temu_category_search.py:158
Finding

Bearer Credentials Can Be Sent to an Arbitrary API Origin

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:74
Finding

Bearer Tokens Are Mirrored into Project and Working Directories

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Installation Is Not Reproducible or Integrity-Pinned

Content
View full analysis
=4.0,<5.0 ``` The Skill instructs users to install the dependency with: ```text python3 -m pip install -r requirements.txt ``` ### Technical Analysis The requirement allows any `platformdirs` release from version 4.0 up to, but excluding, version 5.0. It does not pin an exact audited version and does not provide package hashes. No evidence was found that `platformdirs` is malicious or that the package name is a typosquat. The risk arises from mutable dependency resolution: two installations at different times can retrieve different package contents while both satisfy the requirement. If the package index, publisher account, distribution artifact, or dependency-resolution environment is compromised, installation may retrieve an unexpected release. Python package installation can execute build-backend behavior when a source distribution is selected. ### Attack Path 1. A user follows the Skill instruction to run `pip install -r requirements.txt`. 2. The package resolver selects any available release satisfying `>=4.0,<5.0`. 3. A newly released, compromised, or substituted artifact is selected. 4. Pip downloads and installs that artifact. 5. Malicious build or package code executes with the privileges of the user running pip. 6. The installed code is later imported by `scripts/geekbi_auth.py`. ### Impact Assessment Exploitation could execute code with the privileges of the user performing installation. That could expose project data, user files accessible to that account, environment credentials, and stored GeekBI authentication state. The current project provides no evidence that this attack has occurred. The finding concerns avoidable supply-chain exposure and non-reproducible installation rather than a confirmed malicious d ...[truncated 16 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims rich category-search and analytics features, but the detected implementation reportedly only performs site-list lookup and site-name resolution. This functional mismatch can mislead users and reviewers into trusting business outputs that are not actually produced, and it may conceal unrelated code paths or create unsafe downstream decisions based on false assumptions about what the skill does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims rich category-search and analytics features, but the detected implementation reportedly only performs site-list lookup and site-name resolution. This functional mismatch can mislead users and reviewers into trusting business outputs that are not actually produced, and it may conceal unrelated code paths or create unsafe downstream decisions based on false assumptions about what the skill does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction "安装后直接用中文描述目标即可" imposes a specific language for use in natural-language guidance. This is a locale/language restriction presented without user opt-in or justification, which matches the policy-violation category for forced language usage.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes file reads, shell commands, package installation, and networked scripts, but does not declare any explicit tool scope or allowed-tools policy. This increases the risk of over-privileged execution, accidental command use, and review blind spots because operators cannot easily tell what capabilities the skill requires before running it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L03 将触发条件表述为“用户提到 Temu 类目搜索、类目 ID、类目路径、热销类目、蓝海类目、品类规模、类目趋势、供需竞争或类目机会时使用”,其中多个短语如“类目 ID”“类目趋势”“类目机会”范围较宽,且未提供边界、排除条件或负例。对于 markdown 技能说明,这类宽泛自然语言触发器可能覆盖普通讨论场景,增加非预期调用风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L19 明确要求“输出中文业务结论”,这构成固定语言要求。文件中未见用户可选择语言、按用户输入语言回复,或说明该技能仅限中文场景的明确约束,因此符合语言/locale 策略违规特征。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing metadata in the manifest is written only in Chinese, which can impose a language-specific experience without any visible opt-in or justification in this file. The policy requires avoiding forced language or locale constraints unless the user is given a choice or the restriction is clearly documented as necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt and short description activate the skill for broad requests like searching and analyzing Temu category opportunities without clear user-consent or scope constraints. This can cause the agent to invoke the skill in situations where the user did not explicitly request external marketplace analysis, leading to overbroad data access or unintended tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L117 要求“面向用户只提示该中文文案”,这属于自然语言层面的语言/locale 强制约束。文档没有说明这是仅面向中文用户的区域性技能,也没有提供语言选择或用户同意机制,因此符合语言策略违规特征。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains the module docstring, CLI description, help text, and error/action messages entirely in Chinese, which imposes a specific language on users. The file does not offer any user opt-in, locale selection, or justification that the skill is intended only for a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's user-facing natural-language strings, including the module docstring, CLI description, help text, and validation/error messages, are all hardcoded in Chinese. That imposes a specific language/locale on users without offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python skill contains its docstring, CLI description, help text, and error messages entirely in Chinese, which effectively forces a specific language for users interacting with the tool. The file does not offer language selection or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs the runtime to install dependencies with pip without clearly warning that this mutates the local environment. Allowing a skill to alter the host environment can introduce unreviewed packages, dependency confusion or supply-chain risk, and persistent changes that affect other tasks beyond this skill's scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L07 明确规定“默认使用简体中文”,属于语言输出策略,但文档中没有说明可根据用户偏好切换语言,也未提供显式 opt-in/opt-out 机制。按规则,这类强制或默认限定语言的自然语言要求可能构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.