Back to skill

Security audit

极鲸云 Temu 关键词搜索

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned for GeekBI Temu keyword research, but it stores and reuses GeekBI login state across multiple local locations and Temu skills.

Review this skill before installing if you are uncomfortable with shared GeekBI login state. It should be used only in workspaces where creating a local .geekbi/agent-auth.json file is acceptable, and users should clear the stored auth state when they no longer want the agent to reuse the GeekBI session.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read local reference files, invoke Python scripts, and perform external lookups while the metadata does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user or platform expectations, increasing the risk of unintended file access, shell execution, or network use through an apparently low-privilege skill.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The document explicitly instructs the skill to reuse authentication state across different Temu skills and to persist credential-related state in multiple locations, including a shared system path and per-skill/current-working-directory files. That broadens access to sensitive auth material beyond the minimum needed for a keyword-search skill and increases the chance of unintended disclosure, cross-skill privilege leakage, or token reuse by unrelated code running in the same environment.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.