Back to skill

Security audit

购物省钱攻略

Security checks for vulnerabilities and agentic risk

Overview

This shopping coupon skill mostly does what it says, but it can run a local self-update command and ships exposed API credentials and unsafe temporary caching.

Review this skill before installing. It appears intended for Chinese-language shopping deals and does not show user data exfiltration, but it contacts a third-party coupon service, includes exposed service credentials, writes a shared temporary cache, and can update its own installed package through the local ClawHub CLI when prompted. Prefer a version that removes in-band self-update, rotates and protects API credentials, and stores cache data in a private per-user directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get_coupon.py:22
Finding

Hard-Coded API Credentials Exposed and Transmitted to an External Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_coupon.py:17
Finding

Predictable Shared Temporary Cache Allows Cache Poisoning and Symlink Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is a simple shopping-deals helper, but the detected behavior includes outbound third-party API calls, embedded credentials, local cache read/write activity, and execution of an external self-update subprocess. That mismatch is dangerous because it conceals materially sensitive behaviors, including secret exposure and arbitrary command execution pathways, which can be abused far beyond the user’s reasonable expectations for a shopping skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no permissions or allowed-tools, yet the analyzed behavior indicates file access, network access, shell execution, and file writes. This creates a transparency and sandboxing gap: reviewers and orchestrators cannot accurately constrain what the skill may do, increasing the risk of unauthorized data access, external exfiltration, or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger terms are broad enough to match ordinary shopping-related conversation, which can cause the skill to activate in contexts the user did not intend. Because the skill appears to have network, file, and shell-capable behavior, overbroad invocation materially raises the chance of unnecessary data processing or unintended execution of risky functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example phrases are short, ambiguous, and unconstrained, making accidental invocation likely. In a skill with hidden external calls and execution-related capabilities, ambiguous examples amplify risk by encouraging activation from generic product discussions rather than explicit consent to use a third-party shopping aggregator.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python skill contains user-facing comments, prompts, help text, and output entirely in Chinese, and the interaction flow assumes Chinese-language commands such as "升级" and example queries like "外卖优惠". That creates a language/locale policy issue because the skill enforces a specific language without offering the user any explicit language selection or opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A coupon helper should provide shopping advice, but this code also performs privileged local maintenance by upgrading itself. That mismatch is dangerous in agent environments because a benign-looking skill can be prompted into altering local software state, potentially pulling and running new code not reviewed in the current version.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The script can invoke a local subprocess to run clawhub update shopping-helper, which gives a shopping coupon skill the ability to trigger local software maintenance. Even though the command is hardcoded and not shell-injected, executing package/update operations from a user-invokable skill increases the attack surface and could install changed code from an external source if the update channel is compromised or abused.

Content

Scanner excerpt · scripts/get_coupon.py (reported line 189)May include surrounding context.

python
print(f"🔍 正在检测 {SKILL_NAME} 最新版本...\n")
    
    try:
        result = subprocess.run(
            ["clawhub", "update", SKILL_NAME],
            capture_output=True,
            text=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill metadata and apparent purpose are shopping/coupon assistance, but the runtime behavior includes software update functionality. This makes the context more dangerous because users or orchestrators may grant the skill broader trust than warranted, not expecting it to execute local maintenance commands based on conversational triggers like '升级'.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions and examples are presented only in Chinese, and the skill does not state that language selection is optional or limited to a China-specific audience. This can constitute a language/locale policy issue when a skill implicitly enforces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.