Back to skill

Security audit

Taobao Hot Cn

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a harmless local Taobao shopping-advice demo, but its marketing overstates that it discovers live trends or deals.

Install only if you want static Taobao category, pricing, and seasonal selling suggestions. Do not treat its output as current marketplace data, live trends, or verified best deals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises discovery of trending products, hot categories, and best deals. However, the code does not query Taobao, inspect products, analyze trends, or identify deals. It only accepts a category and optional price range, then outputs hard-coded price distribution data and canned pricing recommendations for categories like clothing, cosmetics, and electronics. This is a materially different primary purpose: pricing guidance rather than product/discovery intelligence. No extra sensitive permissions or resource access are present, but the description does not accurately represent the implemented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a discovery capability that implies obtaining current Taobao hot products, category trends, or deals. In the code, the category handling is entirely static: it returns predefined lists and generic advice without querying Taobao, analyzing live data, or identifying actual deals.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill is presented as a general product-discovery tool, but all example inputs and one use case assume Chinese-language queries and a China-specific marketplace context. There is no explicit notice that the skill requires Chinese terms or that it is limited to a Chinese locale, which can be a natural-language locale policy issue when users are not given a choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents all user-facing output in Chinese, including the title, usage context, and recommendations, with no indication that the skill is region-specific or that another language is available. Under the policy for natural-language constraints, forcing a specific language without user opt-in is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script presents all user-facing text in Chinese, including usage instructions, category names, and results, without offering an alternative language or any opt-in mechanism. Under the natural-language policy rules, forcing a specific language without user choice is a locale-policy issue unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains user-facing strings and usage instructions only in Chinese, which effectively forces a specific language for users. Under the policy, language constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

All visible prompts, labels, and usage instructions are written in Chinese, which imposes a specific language on users. Under the policy rule, this is a natural-language locale constraint that should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.