Back to skill

Security audit

Loss Items 查询(复购商品)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a read-only business API query tool, but it uses an environment token to fetch internal records and its activation scope is broad enough to merit review before installation.

Install only if you trust the publisher and intend this skill to query the Alibaba internal loss-items endpoint with LOSS_API_TOKEN. Use a read-only, narrowly scoped token if possible, and consider tightening trigger phrases so generic requests like pending or page 2 do not accidentally fetch internal business records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tainted flow: 'headers' from os.getenv (line 38, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · query_loss_items.py (reported line 44)May include surrounding context.

python
}

    try:
        resp = requests.get(url, headers=headers, params=params, timeout=15)
        resp.raise_for_status()
        data = resp.json()
        print(json.dumps(data, ensure_ascii=False, indent=2))  # 返回原始 JSON,Skill 会自动总结

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

代码的核心行为是调用一个固定的 loss-items 查询接口,按分页、状态、排序等参数获取列表数据。这与声明中“支持分页、状态、排序等参数、直接调用业务 HTTPS 接口”的部分一致,但声明还包含“待复购商品/待购买商品/商品补货”等能力,代码中完全没有对应实现,也没有切换不同资源类型或执行补货相关操作。因此描述明显宽于实际行为,存在实质性描述与行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to environment secrets and makes business HTTPS calls, but it does not define any explicit tool or permission scope. That weakens least-privilege controls and can allow the skill to run with broader capabilities than users or platform policy expect, especially since it uses a configured API token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description does not disclose that it accesses a business HTTPS API with a configured token, which undermines informed consent and makes the external data flow less visible to users and reviewers. In this context, hidden authenticated network access is materially sensitive because it involves internal business data and a secret-backed integration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary shopping, pagination, or list-query requests that may not be intended for this business integration. In context, that is risky because invoking the skill causes an authenticated API call using a configured token, so accidental activation can disclose internal business data or create unexpected external requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation examples are ambiguous and do not clearly separate this skill from general requests like 'page 2' or 'view items,' which increases the chance of unintended execution. Because the skill performs authenticated business API access, ambiguous routing can expose internal records to users who only made a generic request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file reads the sensitive environment variable LOSS_API_TOKEN and uses it as a Bearer token in a network request. Although there is an internal comment, there is no user-facing warning, confirmation, or visible disclosure that credentials will be read and transmitted to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file contains natural-language comments and error output in Chinese, including the user-visible error message on missing LOSS_API_TOKEN. This imposes a specific language/locale without offering the user any language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.