Back to skill

Security audit

极鲸云 Temu 图搜同款/商品图片搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the advertised Temu image-search task, but it stores login tokens in multiple local places and allows images or requests to be sent to overly broad network destinations.

Review before installing. This skill will upload product images to GeekBI and reuse a local GeekBI login. Install only if you are comfortable with those images leaving your environment, and avoid using it on private/internal image URLs. The publisher should restrict API destinations to the declared GeekBI HTTPS origin and store tokens in one protected user-level location rather than mirroring them into project or skill directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/temu_image_search.py:258
Finding

Unrestricted API origin allows sensitive image transmission to untrusted or plaintext endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/temu_image_search.py:185
Finding

User-controlled image URLs enable server-side request forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:68
Finding

Bearer authentication state is unnecessarily replicated into Skill and workspace directories

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to perform image upload and visual product search, but the reported implementation instead queries site-list resources and lacks the advertised image-processing and filtering functionality. This is dangerous because operators and users may grant network and shell privileges based on a false understanding of purpose, while the actual code path does something else and evades meaningful review or policy controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to perform image upload and visual product search, but the reported implementation instead queries site-list resources and lacks the advertised image-processing and filtering functionality. This is dangerous because operators and users may grant network and shell privileges based on a false understanding of purpose, while the actual code path does something else and evades meaningful review or policy controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says "安装后直接用中文描述目标即可", which directs users to interact in Chinese only. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of file reads, network access, and shell execution but does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent may invoke powerful capabilities implicitly, increasing the chance of overbroad file access, unintended command execution, or network exfiltration without clear policy gating.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件适用 SQP-1。L03 在调用描述中列出“根据商品图片判断选品机会”等较宽泛的触发语义,且整段触发表述为长串场景枚举,没有明确排除条件或负例,容易与一般商品分析/选品讨论重叠,导致技能在并非明确要求图搜时被调用。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L14 明确规定“面向用户使用中文业务名称”,属于对输出语言/语言风格的强制约束。根据规则,若未提供语言或地区选择、也无清晰的合规性理由,则构成自然语言层面的语言/locale 政策违反。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction requires using the server-returned Chinese msg to prompt the user, which imposes a specific language on all users. Under the policy, forcing a language without user opt-in or a documented, justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document explicitly instructs all Temu skills to share one authentication state and to persist credentials in multiple locations, including a shared system path and per-skill/current-working-directory copies. That broadens credential exposure beyond the minimum scope of this image-search skill and increases the chance of unintended cross-skill access, token leakage, or reuse by less-trusted skills operating under the same environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, beginning with the module docstring and continuing throughout exceptions and CLI messages. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

When given an http/https image URL, the script fetches the image from a remote host and then uploads the image to an external API service, but there is no explicit user-facing consent or warning at the point of transmission. This can leak sensitive internal URLs, metadata, or private image contents and is more concerning in an agent context where inputs may come indirectly from users or other tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language strings for the module docstring, CLI description, argument help text, and error messages exclusively in Chinese. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy violation applicable to all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The display name, description, and default prompt are written entirely in Chinese, with no indication that language selection is optional or that the skill is limited to a Chinese-speaking context. This can violate a language/locale policy when users are not given an explicit opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The module docstring and user-facing messages are written in Chinese, and the file does not indicate that language is configurable or user-selectable. This can violate a language or locale policy when skills must not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest says the skill supports local images, session attachments, image URLs, Data URI, Base64, and standard input for Temu image search. The implementation additionally accepts generic file:// URIs and arbitrary http/https URLs directly from the CLI, which broadens input acquisition behavior beyond the manifest's explicitly stated user-facing sources such as session attachments and may reach arbitrary local or remote content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.