Back to skill

Security audit

Taobao Image Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for Taobao image search, but it stores reusable login sessions and can automatically add items to a live shopping cart without a strong confirmation gate.

Review this before installing if you use a real Taobao account. Use it only on a trusted personal machine, treat verification-artifacts/taobao-storage-state.json and .pw-user-data-taobao/ as account credentials, delete them when finished, and avoid running the full script unless you explicitly want it to add a selected item to your cart. Pin Playwright and use a lockfile before using this in a sensitive environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:3
Finding

Unpinned Playwright Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
auto-login-taobao.js:89
Finding

Reusable Taobao Session Credentials Are Persisted Without Permission Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comment frames the file as a 'local verification runner', but the implementation logs into Taobao, uploads an image, selects a product, and performs a real '加入购物车' action. This mismatch is dangerous because users or downstream agents may treat it as non-destructive verification while it actually changes account state on a live third-party service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx playwright without pinning a specific package version, which can cause installation or execution of whatever version is current at runtime. In a skill that automates login and explicitly stores active Taobao session cookies locally, an unpinned toolchain increases supply-chain risk because a compromised or breaking upstream release could execute code in the same environment that handles live browser sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx playwright without pinning a specific version, which can fetch and execute whatever package version is current at install time. This creates a supply-chain risk: a compromised upstream release or unexpected breaking change could result in execution of unreviewed code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install step uses npx playwright without pinning an exact version, so execution depends on whatever package version is currently resolved from the registry at runtime. This creates a supply-chain risk: a malicious or compromised newly published version, or an unexpected breaking update, could run arbitrary install-time code or alter browser automation behavior on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script saves Taobao browser storage state to a local JSON file after login, which can include cookies and session tokens that allow account reuse without re-authentication. Although it prompts the user to log in, it does not clearly disclose before collection that persistent authentication material will be written to disk and retained in a predictable location, increasing the chance of credential leakage from local compromise, backup systems, or accidental sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs a real add-to-cart operation automatically once a logged-in session is present, with no interactive confirmation, safeguard flag, or final prompt. In an agent-skill context, this is more dangerous because it can silently mutate a user's e-commerce account and trigger unintended cart pollution or follow-on purchasing workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that other language options are available. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The browser context is hard-coded to use zh-CN, and the script's user-facing messages are also in Chinese. This imposes a specific language/locale without opt-in, which matches the language-policy violation criteria for natural-language policy concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains multiple user-facing console messages exclusively in Chinese, such as error, status, and login instructions. The file provides no indication that the user can choose a language or that the Chinese-only locale is an intentional, documented constraint, which creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script hardcodes locale: 'zh-CN' when creating the browser context, which enforces a specific locale regardless of user preference. This is a natural-language policy concern because the file does not offer an opt-in or explain why the locale restriction is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.