T09 · Insecure Skill Coding Practices
- Location
scripts/temu_goods_search.py:98- Finding
Unvalidated Base URL Controls Authentication and Credential Transmission
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely matches its Temu product-search purpose, but it handles login tokens and remote links with broader local persistence and weaker destination controls than users are likely to expect.
Review this skill before installing if you are comfortable with GeekBI authentication being reused across Temu skills and stored in multiple local locations, including the current workspace. Use only the default GeekBI endpoint, avoid passing custom --base-url values, and treat any login, payment, upgrade, or product links shown by the skill as external links that should be verified before opening.
scripts/temu_goods_search.py:98Unvalidated Base URL Controls Authentication and Credential Transmission
scripts/geekbi_auth.py:60Bearer Authentication State Is Unnecessarily Replicated Across Multiple Directories
scripts/geekbi_auth.py:497Server-Controlled Messages and URLs Are Treated as Trusted Agent Output
requirements.txt:1Third-Party Dependency Is Not Reproducibly Pinned
The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.
The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.
The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.
The README instructs users to 'directly use Chinese' to describe their goal, which imposes a specific language requirement in natural-language documentation. This is a locale/language policy concern because the file does not present Chinese as optional or provide a justified region-specific limitation.
The skill advertises and instructs use of shell scripts, file reads, and network-backed queries, but it does not declare any explicit tool scope or permission boundaries. This weakens governance and review because an executor may grant broader capabilities than users expect, increasing the chance of unintended file access, command execution, or outbound requests.
The instructions require the skill to '默认使用简体中文' and further state '面向用户使用中文业务名称', which imposes a language policy on user-facing behavior. This is a natural-language policy concern because the file does not offer an opt-in, fallback, or user choice for other languages/locales.
The document instructs that user-facing failures should show only '该中文文案', which imposes a specific language on the user. Under the policy, forcing a language/locale without user opt-in is a natural-language policy violation unless a justified locale constraint is documented, which is not present here.
The document explicitly states that all Temu skills share a single authentication state and reuse login status across skills. This expands the trust boundary beyond the stated product-search purpose and creates unnecessary credential sharing between independently scoped skills, increasing the chance that another skill can access or misuse authentication material or perform actions under the same session.
The instructions allow saving login credentials to the current skill directory and current working directory, both of which are commonly accessible to other processes, users, tools, backups, or source-control workflows. Writing secrets to multiple local files materially increases the attack surface for credential theft and accidental disclosure, especially in an agent environment where working directories may be inspected or persisted.
The markdown instructs the system to persist login credentials in multiple local files but provides no user-facing warning, consent, retention policy, or disclosure of the privacy and security implications. In a product-search skill, silent credential persistence is not necessary to the user-facing function and makes misuse or surprise exposure more likely.
The clear_auth_state function unlinks authentication state files from multiple locations, which is a destructive local file operation affecting login persistence. Although the CLI exposes a 'clear' command, there is no confirmation prompt, user-facing disclosure in the function path itself, or warning comment/docstring explaining that stored login state will be removed.
The natural-language description and user-facing messages are entirely in Chinese, and the CLI help specifically requests Chinese or English country names, but the skill does not offer a language/locale choice or explain that it is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in is a locale policy concern.
The display name, description, and default prompt are all written only in Chinese, which can constitute a language/locale policy issue when no user opt-in or region-specific justification is provided. The file does not indicate that the skill is limited to Chinese-speaking users or offer an alternative language option.
Line L10 states that the skill will default to Simplified Chinese output. This is a natural-language locale policy constraint, and the file does not indicate that users are offered a language choice or asked to opt in before this default is applied.
The module docstring is written only in Chinese and the CLI descriptions/messages throughout the file are also fixed to Chinese, with no indication that users can choose another language. This is a natural-language locale constraint embedded in the skill that may violate organizational language-choice policy when no opt-in or justification is provided.
This code sends a request to an external service using authenticated_json_request, which may transmit user-provided input and authenticated context. While the script's purpose implies a lookup, the file does not include any explicit comment, docstring detail, or user-facing notice that it contacts a remote API.
No suspicious patterns detected.