Back to skill

Security audit

极鲸云 Temu 关键词搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real GeekBI Temu keyword-search helper, but it stores login tokens in extra local folders and trusts server-supplied links, so it should be reviewed before installation.

Install only if you trust GeekBI and are comfortable with the skill saving authentication state locally. Avoid running it from shared, synced, or version-controlled workspaces until token storage is limited to a protected user config or credential store, and do not use custom base URLs unless you control and trust the endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/geekbi_auth.py:267
Finding

Authentication Tokens Are Mirrored into Skill and Working Directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/temu_keyword_search.py:155
Finding

Arbitrary and Plaintext Authentication Endpoints Are Accepted

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:372
Finding

Server-Controlled Links Are Displayed without Scheme or Host Validation

Content
View full analysis
)`。不要添加裸链接列、改写链接或用“查看详情”替代名称。 - 发送答复前检查:非空 `linkUrl` 的关键词数量必须与可点击关键词名称数量一致。 ``` ### Technical Analysis The authentica ...[truncated 1990 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is Temu keyword analysis, but the observed behavior includes invoking a site-list lookup flow instead of directly performing keyword analysis. Description-behavior mismatches are dangerous because they undermine user consent and reviewer trust; a skill can appear narrowly scoped while actually accessing different resources or performing unexpected actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says '安装后直接用中文描述目标即可', which imposes Chinese as the interaction language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to read local reference files and execute Python scripts, which implies file, shell, and likely network capabilities, but it declares no explicit tool scope or allowlist. This weakens least-privilege controls and can let a broader tool-enabled runtime execute actions the user did not clearly authorize, increasing the blast radius if the skill is misused or modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L11 states the skill will '默认使用简体中文' (use Simplified Chinese by default). This imposes a language choice without indicating user consent or offering a language option, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The display name, description, and default prompt are entirely in Chinese, which implies a fixed language choice for the skill experience. There is no indication that users can choose another language or that the locale restriction is intentional and documented for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L126 says that when exit code is 1, the user should be shown only the Chinese message text. This imposes a specific language on the user without opt-in or any documented locale justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file uses natural-language strings that explicitly define the skill as a Chinese-language login/status manager, and all user-facing messages/help text throughout the file are in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or a documented region-specific justification is a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The clear_auth_state function unlinks authentication state files from multiple storage locations, which is a destructive operation affecting persisted login data. The function itself contains no confirmation prompt, warning comment/docstring, or user-facing disclosure at the point of deletion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing descriptions, help text, and error messages entirely in Chinese, including the module docstring, CLI argument help, and runtime error/output strings. Because the skill does not offer a language/locale option or document that it is intentionally limited to Chinese-speaking users, it appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says '默认使用简体中文', which imposes a language default in the skill's responses. Under the policy, forcing a specific language without explicit user choice or opt-in is a natural-language policy concern unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language strings entirely in Chinese, including the module docstring, argument descriptions, and runtime error messages. Under the policy rule for language/locale, forcing a specific language without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.