Back to skill

Security audit

极鲸云 Temu 数据分析与市场调研

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Temu research purpose is coherent, but it requires unvalidated service-provided links in user answers and can fetch then upload arbitrary image URLs, so it should be reviewed before installation.

Install only if you trust GeekBI’s API responses and are comfortable with the skill storing login state in your user configuration directory. Treat all returned clickable links and login/action links as third-party service-provided destinations, and avoid giving image URLs that point to localhost, private networks, internal dashboards, or sensitive local files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Mandatory Injection of Server-Controlled Links into Agent Responses

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/geekbi_auth.py:585
Finding

Unvalidated Server-Controlled Authentication and Action Redirects

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/temu_image_search.py:111
Finding

Arbitrary Image URL Fetching Enables SSRF and External Disclosure of Retrieved Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Overly broad trigger phrases can cause the skill to activate in conversations that only loosely resemble Temu research, increasing the chance it accesses external services or routes user data unnecessarily. In an agent ecosystem, overbroad invocation widens the effective attack surface and can lead to unintended data handling without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions require the skill to '默认使用简体中文' and to use only Chinese business names for user-facing output. This imposes a language policy on users without offering a choice or opt-in, which is a natural-language locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name, short description, and default prompt are all written exclusively in Chinese, which indicates the skill is effectively constrained to a specific language/locale. There is no visible opt-in, language selection mechanism, or documented justification that this skill is intentionally region-specific, so this creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L10 states that the skill should default to Simplified Chinese output. Under the policy criteria, language constraints should not be imposed without user opt-in or an explicit choice mechanism, and this file does not indicate such a choice is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L65 instructs that when the server returns a top-level msg, the skill must show only that Chinese text to the user. This imposes a specific language on user-facing output without offering language choice or documenting a justified locale restriction, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

L117 明确要求“面向用户只提示该中文文案”,这构成了固定语言输出约束。根据规则,若未提供语言/locale 选择或未说明这是合理的区域限定工具,则属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L134 明确要求“面向用户只提示该中文文案”,这属于自然语言层面的固定语言要求。文档中没有说明可根据用户语言偏好切换,也没有给出用户选择语言的选项,因此存在语言/locale 策略违规风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires presenting results to users using Chinese business names and avoids exposing original command/parameter forms. This imposes a specific language/locale behavior without offering the user a choice or documenting opt-in, which matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says to use the server-returned Chinese message to prompt the user, which imposes a specific language on user-facing output. The file does not offer user opt-in, fallback language handling, or a documented region-specific justification for requiring Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file instructs the skill to use script-generated Chinese errors when no valid server prompt exists. This is a natural-language locale requirement that applies regardless of user preference and is not justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains multiple natural-language strings in Chinese for its docstring, CLI description, help text, and error messages. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-facing docstrings, argument descriptions, and error messages are written only in Chinese. This effectively forces a specific language for all users, and the file does not provide opt-in language selection or explain that the skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings such as the module docstring, argument descriptions, and error messages only in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's docstring, CLI help text, and runtime error/output messages are all written in Chinese, which imposes a specific language on users. The policy allows locale constraints when user choice or clear justification is provided, but this script does not offer an opt-in or document that it is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says '安装后直接用中文描述目标即可', which imposes Chinese as the interaction language in the skill description. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless alternatives or justification are provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions state that the skill should default to Simplified Chinese and that progress updates, analysis, and final responses should use Chinese business terms. This is a natural-language locale constraint that applies regardless of user preference, and the file does not indicate a user choice or opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions require the skill to default to Simplified Chinese and further require progress updates, analysis, and final responses to be in Chinese. This is a natural-language locale policy constraint presented without offering the user a language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions state that responses, progress updates, and final answers should use Chinese by default, and technical information should also be hidden unless explicitly requested. This is a natural-language locale policy constraint that does not offer the user a language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L08 states '默认使用简体中文和绝对日期', which imposes a specific language default in the skill instructions. Under the policy rule, forcing a language or locale without explicit user opt-in can be a natural-language policy violation unless a justified regional constraint is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python skill uses Chinese-only natural-language descriptions and user-facing messages throughout, starting with the module docstring and continuing in CLI/help text, without offering a language choice or documenting that the skill is intended only for a Chinese-speaking environment. That creates a locale-policy concern under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script accepts arbitrary http/https URLs and local file paths, then reads and uploads the resulting image content to an external API. In an agent/skill context, this can enable SSRF-like access to internal network resources or unintended exfiltration of local files if user-controlled input is passed through without clear trust boundaries or consent prompts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.