Back to skill

Security audit

uniqlo(优衣库)-product-query

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it queries Uniqlo China discount products and saves a local Markdown report, with some disclosure and dependency hardening gaps.

Before installing, understand that using this skill will contact Uniqlo China's API and create timestamped Markdown files in a unique/ folder under your current working directory. Install it in an isolated environment and consider pinning dependencies if you need reproducible or security-reviewed deployments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Prevents Reproducible Installation

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, line 1
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

Vulnerable Code

text
requests

The documented installation procedure in README.md, lines 25–27, consumes this unconstrained requirement:

bash
pip install -r requirements.txt

Technical Analysis

The project declares requests without a version constraint or package hash. Consequently, installation resolves whichever compatible release is available from the configured package index at that time. The resulting environment is not reproducible and may differ from the dependency version that was present when the project was reviewed.

This is a supply-chain hardening weakness rather than evidence that the current requests package is malicious. Exploitation would require an attacker to compromise the selected package release, its dependency chain, or the package-index resolution path. Pinning only requests is not sufficient for full reproducibility because its transitive dependencies must also be locked and verified.

Attack Path

  1. A user follows the documented installation procedure.
  2. pip resolves the unconstrained requests requirement and its transitive dependencies from the configured package index.
  3. If a resolved release or index path has been compromised, attacker-controlled package code is installed.
  4. The application imports requests from uniqlo_product_query.py.
  5. Malicious dependency code can execute with the privileges of the user or service running the skill.

This path is conditional on an upstream package, transitive dependency, package index, or resolution channel being compromised; no such compromise was identified in the audited files.

Impact Assessment

Successful exploitation could execute arbitrary Python code with the skill process's permissions. This could expose files, environment variables, and network resources accessible to that process, or a ...[truncated 165 chars]

Remediation
View remediation

Remediation Suggestions

  1. Generate a reviewed lock file containing exact versions for requests and every transitive dependency.

  2. Include cryptographic hashes for all permitted distributions and enforce them during installation:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Generate pins using a dependency-locking tool such as pip-tools, and commit both the source dependency declaration and generated lock file.

  4. Use a trusted package index over TLS and explicitly control package-index configuration in deployment environments.

  5. Run dependency vulnerability and provenance checks in CI.

  6. Review and deliberately update pinned versions on a regular schedule so security patches are not indefinitely blocked.

  7. Install and run the skill in an isolated, least-privileged environment.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

整个 README 仅以中文描述技能名称、触发词、输入输出示例和返回格式,且触发条件完全依赖中文关键词,没有说明是否支持其他语言或是否仅面向特定中文用户群体。根据规则,强制特定语言但未提供用户选择或合理限定,属于自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough that ordinary shopping-related phrases can activate the skill unintentionally. Because the skill performs external API requests and writes output files, accidental invocation can cause unintended network activity, unnecessary file creation, and user-surprising behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation does not clearly disclose that the skill will contact an external Uniqlo API and create files under the working directory. Lack of transparency weakens user consent and makes it easier for data egress or filesystem side effects to occur without the operator realizing the skill's behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises behavior that performs both network access and local file writes, but it does not declare any explicit tool scope or permissions. That creates a capability/transparency gap: an orchestrator or reviewer cannot easily enforce least privilege, and users may invoke the skill without understanding it will contact an external API and write files locally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation description uses broad retail terms like sales, discounts, promotions, and category words, which can cause the skill to trigger in conversations where the user did not specifically intend to run it. Because the skill performs network requests and writes Markdown files, accidental activation can lead to unintended external calls and filesystem side effects rather than being merely a relevance issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description centers invocation on Chinese terms and states that the skill queries Uniqlo's Chinese API, but it does not indicate that this locale/language constraint is optional or user-selectable. This can violate language/locale policy expectations when a skill implicitly restricts interaction to a single language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API endpoint is hardcoded to the zh_CN locale, and the skill’s natural-language interface and responses are entirely in Chinese. This imposes a language/locale choice on users without opt-in or explanation, which matches the policy-violation category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · uniqlo_product_query.py (reported line 299)May include surrounding context.

python
headers = {"Content-Type": "application/json"}
    
    try:
        response = requests.post(API_BASE_URL, json=payload, headers=headers, timeout=API_TIMEOUT)
        response.raise_for_status()
        api_response = response.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill writes files and creates a directory on disk automatically without explicit user confirmation or a clear pre-action warning. In an agent setting, silent file creation can surprise users, clutter the workspace, or be abused to persist artifacts locally when the user expected only a conversational answer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill writes Markdown reports to the local filesystem, but the user-facing description does not clearly warn about that side effect. Hidden or poorly disclosed file creation reduces informed consent and can surprise users in constrained environments, especially if repeated invocations generate many files in the working directory.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency file specifies requests without a version pin, which makes builds non-reproducible and can result in installing an outdated or incompatible release with known security issues. In a skill that queries external product data over the network, the HTTP client library is security-relevant because its behavior directly affects TLS validation, redirect handling, and credential exposure risks.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Because requests is unpinned, it is impossible to verify whether deployment will use a patched or vulnerable version despite multiple known advisories affecting some releases. This skill's purpose involves fetching remote content and links, so using a vulnerable HTTP library could increase exposure to issues such as credential leakage, improper certificate verification behavior, or unsafe redirect handling when interacting with attacker-controlled or compromised endpoints.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated Markdown note says '点击图片可查看大图', implying the image itself is a clickable link. However, the code only inserts a plain tag at L453 and does not wrap it in an anchor tag, so the documentation of the output behavior contradicts the actual generated content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.