Back to skill

Security audit

Taobao Automation

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Taobao operations helper that describes scheduled reports, competitor monitoring, and notifications, with no executable code or hidden install behavior found.

Before installing, confirm what store metrics may be sent to Feishu or WeChat, who can read those channels, and that any competitor monitoring follows platform rules and reasonable rate limits. Review any future implementation code carefully because this package is documentation-only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes scheduled reporting and pushing shop metrics to Feishu/WeChat, but it does not clearly disclose that operational data will be transmitted to external third-party messaging services. This creates a real transparency and data-handling risk because users may enable automation without understanding where business data is sent or what retention and access implications exist.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The competitor-monitoring feature relies on periodic scraping of external pages, but the skill does not clearly warn users about continuous automated access, potential terms-of-service issues, rate limits, or operational impact. In this context, the omission is risky because unattended scraping can cause compliance violations or trigger blocking while users may not realize the automation is persistent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

整份技能说明、示例命令和交互内容均默认要求中文表达,且没有提供语言/地区选择或声明该限制的业务必要性。根据语言/locale 政策,这种未说明的单一语言约束可能构成自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The command for daily reminders implies creation of a persistent scheduled monitoring and notification workflow, but the documentation does not clearly tell users that this will continue running and may send data outward on a recurring basis. This is a smaller but real vulnerability in user awareness and consent, especially when combined with external notification channels.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.