Back to skill

Security audit

极鲸云 Temu 店铺搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Temu shop-search purpose, but it stores GeekBI login tokens in multiple local folders including the current workspace, which needs review before installation.

Install only if you are comfortable with GeekBI API requests and local GeekBI session reuse. Before using it in sensitive or shared workspaces, consider that login tokens may be copied into a hidden .geekbi folder in the current project and skill directory as well as user config; avoid running it from repositories or folders that may be archived, synced, or shared, and clear the auth state if exposure is a concern.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/geekbi_auth.py:53
Finding

Authentication Tokens Are Replicated into Skill and Working Directories

Content
View full analysis

Vulnerability Details

File Location: scripts/geekbi_auth.py:53-78, scripts/geekbi_auth.py:299-320, and scripts/geekbi_auth.py:631-650
Vulnerability Type: Plaintext sensitive-data storage and excessive credential replication
Risk Level: Medium

Vulnerable Code

python
def _user_config_state_path():
    return _absolute_path(
        user_config_path("GeekBI", appauthor=False, ensure_exists=True)
        / "temu-research-skill"
        / AUTH_FILE_NAME
    )


def _skill_state_path():
    return _absolute_path(Path(__file__).parent.parent / AUTH_STATE_DIR / AUTH_FILE_NAME)


def _workspace_state_path():
    return _absolute_path(Path(os.getcwd()) / AUTH_STATE_DIR / AUTH_FILE_NAME)


def _resolve_stores():
    candidates = (
        ResolvedStore(_user_config_state_path(), "user-config-directory"),
        ResolvedStore(_skill_state_path(), "skill-directory"),
        ResolvedStore(_workspace_state_path(), "working-directory"),
    )
    stores = []
    seen_paths = set()
    for store in candidates:
        path_key = os.path.normcase(os.fspath(store.path))
        if path_key in seen_paths:
            continue
        seen_paths.add(path_key)
        stores.append(store)
    return tuple(stores)
python
def _write_state_files(stores, payload):
    normalized = _normalize_state(payload)
    errors = []
    written = 0
    for store in stores:
        try:
            _write_state_file(store, normalized)
            written += 1
        except OSError as error:
            errors.append(f"{store.kind}: {_storage_probe_reason(error)}")
    if written == 0:
        reason = ";".join(errors) or "登录状态目录不可用"
        raise OSError(reason)
python
def save_token(latest):
    latest_server = latest["servers"].get(server_key)
    if not isinstance(latest_server, dict):
        return False, False
    latest_pending = latest_serv
...[truncated 3136 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store authentication state only in the protected operating-system user configuration directory.
  2. Remove _skill_state_path() and _workspace_state_path() from _resolve_stores() for production authentication data.
  3. Prefer an operating-system credential manager or keyring for the bearer token; keep only non-sensitive metadata in JSON.
  4. If cross-Skill authentication reuse is required, provide a narrowly scoped local authentication broker rather than a token file readable by every same-user Skill.
  5. Continue enforcing restrictive permissions, atomic replacement, and file locking for any remaining state files.
  6. Add migration logic that securely deletes legacy token copies from Skill and workspace directories after moving the active state to the protected store.
  7. Implement token revocation and rotation controls so users can invalidate a potentially exposed session.
  8. Document the exact storage location and security boundary so users understand which local processes can access the session.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-Party Dependency Is Not Reproducibly Pinned or Integrity-Verified

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1 and SKILL.md:34
Vulnerability Type: Unpinned dependency and missing package-integrity verification
Risk Level: Low

Vulnerable Code

text
platformdirs>=4.0,<5.0

The installation instruction is:

text
python3 -m pip install -r requirements.txt

Technical Analysis

The dependency specification accepts any platformdirs release from version 4.0 up to, but excluding, version 5.0. It does not pin an exact audited artifact and does not provide cryptographic hashes.

Consequently, separate installations can resolve to different package versions. If a future permitted release is compromised, removed and replaced in an unsafe package index, or introduces an exploitable regression, the Skill may install and execute code that was not part of the audited project snapshot.

No evidence was found that platformdirs itself is malicious, that the package name is typosquatted, or that the project uses an untrusted package index. This finding concerns preventable supply-chain exposure and build non-reproducibility.

Attack Path

  1. The execution environment does not already contain the required dependency.
  2. The Agent or user follows SKILL.md and runs the documented pip installation command.
  3. pip queries its configured package index and selects any available release satisfying the broad version range.
  4. A compromised, malicious, or unexpectedly incompatible future release is selected.
  5. Package code executes during installation or when geekbi_auth.py imports platformdirs.

Exploitation depends on compromise or unsafe configuration of the package supply chain; it is not directly triggerable solely through Temu search parameters.

Impact Assessment

Malicious dependency code would execute with the same operating-system privileges as the user running pip or invoking the Skill. Within that user context, it could ...[truncated 326 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact version that has been reviewed and tested.
  2. Generate and commit cryptographic hashes for the approved distribution artifacts.
  3. Require hash validation during installation, such as with pip install --require-hashes -r requirements.txt.
  4. Use a lock file or reproducible dependency-management workflow and review lock-file changes during updates.
  5. Prefer binary wheels from a trusted package index and explicitly configure the expected index where operationally appropriate.
  6. Add automated dependency vulnerability and provenance scanning to the release process.
  7. Test dependency updates before changing the pinned version rather than automatically accepting all future releases within a major-version range.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates another description-behavior mismatch: the skill claims broad shop-search, filtering, ranking, and competitive-analysis features, while the observed implementation apparently performs only site resolution/site list lookup. Such overclaiming can mislead operators into trusting outputs or granting access based on capabilities the skill does not actually implement, undermining security review and operational reliability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates another description-behavior mismatch: the skill claims broad shop-search, filtering, ranking, and competitive-analysis features, while the observed implementation apparently performs only site resolution/site list lookup. Such overclaiming can mislead operators into trusting outputs or granting access based on capabilities the skill does not actually implement, undermining security review and operational reliability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope even though it instructs use of file reads, shell execution, and network-backed scripts. In an agent environment, missing permission boundaries can let the skill invoke broader capabilities than a reviewer or user would expect, increasing the risk of unintended command execution, data access, or network actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L19 instructs the skill to '输出中文业务结论', which forces a specific language for responses. Under the policy, language constraints should either offer user choice or be clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires using the server-returned Chinese msg to prompt the user and later specifies fallback to script-generated Chinese errors. This imposes a specific language on users without opt-in or an explicit documented regional constraint, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file states that when no valid server prompt exists, the script should generate a Chinese error message. This is another explicit locale constraint that does not provide the user a language choice or explain why Chinese-only output is required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs the system to persist login credentials in multiple filesystem locations, including shared and working directories, which materially increases the attack surface for credential disclosure through weak file permissions, accidental inclusion in backups, source control, or access by other local processes. In this skill context, the risk is elevated because authentication state is explicitly shared across multiple Temu skills, so compromise of one location or skill can enable broader unauthorized access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language strings exclusively in Chinese, beginning with the module docstring, and later user-facing CLI/help and error messages follow the same pattern. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains natural-language strings such as the module docstring, argument descriptions, and error messages exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says '安装后直接用中文描述目标即可', which imposes Chinese as the interaction language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The display name, short description, and default prompt are all written in Chinese, which indicates a fixed language/locale presentation. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction says the skill should '默认使用简体中文', which imposes a language preference in the skill's behavior. Under the policy, language constraints should be user-selected, opt-in, or clearly justified as region-specific; this file does not offer a user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This line requires progress explanations, analysis process, and final responses to use Chinese, with no opt-in or alternative locale handling. That is a natural-language locale restriction that should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file consists entirely of Chinese-language instructions and examples, but it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and command-line descriptions are presented exclusively in Chinese, which effectively forces a specific language for user-facing interaction. The file does not offer a language choice or document that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs an authenticated HTTP request to an external service, which may transmit user-provided input and authentication context. Although the file includes error output, it does not provide any user-facing notice, confirmation, or comment/docstring warning that remote API communication will occur.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.