Back to skill

Security audit

1688 Scraper

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent 1688 product scraper, but its URL validation is too loose and could make the browser visit non-1688 or internal hosts before saving scraped data locally.

Review before installing. Use only intended 1688 product URLs, preferably exact https://detail.1688.com/offer/<id>.html links, and expect the skill to create a local image folder and JSON file that may consume disk space or be picked up by desktop backup/sync tools.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scraper.js:17
Finding

Insufficient URL Validation Allows Navigation to Untrusted Hosts

Content
View full analysis
.html`. It does not parse the URL or verify its scheme, hostname, port, credentials, or resolved network address. Consequently, URLs such as the following satisfy the validation rule despite not belonging to 1688: ```text http://127.0.0.1:8080/offer/1.html http://192.168.1.10/offer/1.html https://attacker.example/offer/123.html ``` The current `scraper.js` implementation only creates an output directory and returns a `ready` result; it does not itself invoke `browser.open()`. However, the documented skill workflow explicitly opens the original URL after applying this insufficient validation. Therefore, an orchestrator implementing the documented workflow could navigate its browser to an attacker-selected host. Redirects also require validation. Even if the initial hostname is restricted, an approved URL could redirect the browser to a loopback, link-local, private-network, or unrelated public destination unless every navigation target is checked. ### Attack Path 1. An attacker supplies a URL such as `http://127.0.0.1:8080/offer/1.html`. 2. `extractOfferId()` finds `/offer/1.html` and returns `1`. 3. The caller treats the URL as a valid ...[truncated 1323 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs saving downloaded images and a JSON data package to the user's desktop without any consent, warning, or limits on volume. Automatic local writes can surprise users, consume disk space, and persist scraped marketplace data on the host in ways that create privacy and operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes enumerating network resource URLs via the Performance API and downloading all matching images, but provides no privacy or data-handling notice. This broad collection behavior can capture more assets than a user expects, including indirectly loaded resources, and then persist them locally without minimization or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest explicitly states that scraped images and product data will be written to the user's Desktop, but it does not indicate any user notification, confirmation step, or opt-in before local file creation. Writing files is a sensitive side effect because it persists potentially large or unwanted data on the host, may expose scraped content to other local users or backup/sync services, and can surprise users who only expected data extraction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s user-facing description is entirely in Chinese and presents the skill as a general-purpose product scraper, but it does not offer any language or locale opt-in. Under the policy, forcing a specific language without user choice or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language invocation examples and instructions are entirely in Chinese, and the file does not indicate that another language can be used or that the Chinese locale is an intentional, documented constraint. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes outputs written to the user's desktop as folders and JSON files, which affects local user storage and filesystem state. While file output is part of the skill's purpose, the description does not include any user-facing warning or caution about creating local files and directories or overwriting/accumulating data at the destination path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file explicitly states that the collection process will generate an image folder and a JSON data package on the Desktop, which affects the user's filesystem. Under the markdown-specific warning criterion, the description should disclose this side effect more clearly as a user-facing warning rather than only presenting it as output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.