Back to skill

Security audit

极鲸云 Temu 评论搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Temu review analysis, but it deserves review because it persists login tokens in multiple local locations and allows less-scoped API/link destinations.

Install only if you are comfortable authenticating to GeekBI and having the resulting session state written locally, including possible copies under the skill and current workspace. Prefer using the default GeekBI endpoint, avoid custom base URLs unless you trust the deployment, and clear the auth state when you no longer need the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:367
Finding

Bearer Tokens Are Unnecessarily Mirrored into Skill and Working Directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:693
Finding

Unvalidated Service Origins and Redirects Can Expose Authentication Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is review lookup and analysis, but the underlying behavior reportedly includes authentication flows, token handling, and persistent storage of login state. Hidden auth/state-management behavior is dangerous because it expands the trust boundary beyond simple data retrieval and can expose credentials, create long-lived session artifacts, or enable unintended reuse of privileged access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is review lookup and analysis, but the underlying behavior reportedly includes authentication flows, token handling, and persistent storage of login state. Hidden auth/state-management behavior is dangerous because it expands the trust boundary beyond simple data retrieval and can expose credentials, create long-lived session artifacts, or enable unintended reuse of privileged access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README tells users to '直接用中文描述目标即可', which imposes a specific language for interaction. Under the policy, forcing a language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill declares no explicit tool scope or permissions while its documented workflow invokes local file reads, shell scripts, and network-backed operations. That mismatch weakens least-privilege controls and makes it harder for reviewers or runtime policy to constrain what the skill may access, increasing the chance of unintended data access or command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '使用简体中文' mandates a specific language for all outputs. This is a natural-language policy concern because the file does not offer the user a language choice or frame the locale as an explicit, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name and descriptions are entirely in Chinese, which indicates a language-specific presentation without any visible user choice or documented locale justification in this file. Organizational language policy issues can arise when a skill is constrained to a specific language absent opt-in or a clearly stated region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L08 明确写明“默认使用简体中文和绝对日期”,这是面向用户的自然语言输出策略,但文档中没有说明可根据用户偏好切换语言。根据规则,强制特定语言而缺少用户选择或明确的合理限定,属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L134 明确要求“面向用户只提示该中文文案”,属于对用户输出语言的强制限定。该文件未说明这是仅限中文用户的区域性工具,也未提供用户选择语言或明确的语言适用范围,因此构成自然语言层面的语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file repeatedly requires use of Chinese output, including showing the server's Chinese msg and generating Chinese fallback errors. Under SQP-3, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which this document does not provide.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly instructs that login credentials be stored in multiple filesystem locations, including a shared system user configuration path and per-skill/current-working-directory copies. Persisting authentication material in several places increases the attack surface for credential theft, accidental inclusion in backups or repositories, and cross-skill leakage, especially in a multi-skill environment sharing one auth state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-facing strings including the module docstring, argument descriptions, and error messages are all presented in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest says to use the skill to search and analyze Temu reviews, but it does not define any explicit activation phrases, scope boundaries, or exclusion conditions. In a manifest file, this can make invocation conditions ambiguous because there is no clear indication of when the skill should or should not be selected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's docstring and many user-facing messages are written exclusively in Chinese, indicating the skill is designed to communicate in a single language without any visible user opt-in or locale selection. Under the language/locale policy, forcing one language without offering a choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the module docstring, CLI help text, and error messages are all Chinese-only. Under the stated policy, forcing a specific language without opt-in or documented justification is a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.