Back to skill

Security audit

极鲸云 Temu 商品搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Temu product-search purpose, but it handles login tokens and remote links with broader local persistence and weaker destination controls than users are likely to expect.

Review this skill before installing if you are comfortable with GeekBI authentication being reused across Temu skills and stored in multiple local locations, including the current workspace. Use only the default GeekBI endpoint, avoid passing custom --base-url values, and treat any login, payment, upgrade, or product links shown by the skill as external links that should be verified before opening.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/temu_goods_search.py:98
Finding

Unvalidated Base URL Controls Authentication and Credential Transmission

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:60
Finding

Bearer Authentication State Is Unnecessarily Replicated Across Multiple Directories

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/geekbi_auth.py:497
Finding

Server-Controlled Messages and URLs Are Treated as Trusted Agent Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-Party Dependency Is Not Reproducibly Pinned

Content
View full analysis
=4.0,<5.0 ``` ### Technical Analysis The dependency declaration permits any future `platformdirs` release in the 4.x series. Consequently, two installations performed at different times may execute different third-party code even when the Skill source has not changed. The package name is not a detected typosquat, and the audit found no evidence that the currently intended dependency is malicious. The risk arises from allowing future, unaudited versions and from the absence of package hashes or a lock file. ### Attack Path 1. A future allowed 4.x release is compromised, malicious, or contains a security regression. 2. A user installs or updates the Skill after that release becomes available. 3. The package resolver selects the new version because it satisfies the declared range. 4. The new dependency code executes during installation or when `geekbi_auth.py` imports and uses `platformdirs`. ### Impact Assessment The dependency executes with the same operating-system privileges as the Skill process. A compromised package could therefore access files and credentials available to that user, modify local data, or make network requests. No such compromise was observed in the reviewed artifact; this finding concerns preventable supply-chain exposure and build reproducibility. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description focuses on Temu product search and analysis, but the behavior includes authentication-state persistence, token management, auth HTTP requests, and local storage handling that are not clearly disclosed in the declared purpose. Hidden or under-disclosed auth flows are dangerous because they may cause users or reviewers to miss that sensitive credentials and session artifacts are being stored and reused across contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to 'directly use Chinese' to describe their goal, which imposes a specific language requirement in natural-language documentation. This is a locale/language policy concern because the file does not present Chinese as optional or provide a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises and instructs use of shell scripts, file reads, and network-backed queries, but it does not declare any explicit tool scope or permission boundaries. This weakens governance and review because an executor may grant broader capabilities than users expect, increasing the chance of unintended file access, command execution, or outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require the skill to '默认使用简体中文' and further state '面向用户使用中文业务名称', which imposes a language policy on user-facing behavior. This is a natural-language policy concern because the file does not offer an opt-in, fallback, or user choice for other languages/locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs that user-facing failures should show only '该中文文案', which imposes a specific language on the user. Under the policy, forcing a language/locale without user opt-in is a natural-language policy violation unless a justified locale constraint is documented, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document explicitly states that all Temu skills share a single authentication state and reuse login status across skills. This expands the trust boundary beyond the stated product-search purpose and creates unnecessary credential sharing between independently scoped skills, increasing the chance that another skill can access or misuse authentication material or perform actions under the same session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions allow saving login credentials to the current skill directory and current working directory, both of which are commonly accessible to other processes, users, tools, backups, or source-control workflows. Writing secrets to multiple local files materially increases the attack surface for credential theft and accidental disclosure, especially in an agent environment where working directories may be inspected or persisted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown instructs the system to persist login credentials in multiple local files but provides no user-facing warning, consent, retention policy, or disclosure of the privacy and security implications. In a product-search skill, silent credential persistence is not necessary to the user-facing function and makes misuse or surprise exposure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The clear_auth_state function unlinks authentication state files from multiple locations, which is a destructive local file operation affecting login persistence. Although the CLI exposes a 'clear' command, there is no confirmation prompt, user-facing disclosure in the function path itself, or warning comment/docstring explaining that stored login state will be removed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and user-facing messages are entirely in Chinese, and the CLI help specifically requests Chinese or English country names, but the skill does not offer a language/locale choice or explain that it is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in is a locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, description, and default prompt are all written only in Chinese, which can constitute a language/locale policy issue when no user opt-in or region-specific justification is provided. The file does not indicate that the skill is limited to Chinese-speaking users or offer an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L10 states that the skill will default to Simplified Chinese output. This is a natural-language locale policy constraint, and the file does not indicate that users are offered a language choice or asked to opt in before this default is applied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring is written only in Chinese and the CLI descriptions/messages throughout the file are also fixed to Chinese, with no indication that users can choose another language. This is a natural-language locale constraint embedded in the skill that may violate organizational language-choice policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends a request to an external service using authenticated_json_request, which may transmit user-provided input and authenticated context. While the script's purpose implies a lookup, the file does not include any explicit comment, docstring detail, or user-facing notice that it contacts a remote API.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.