Back to skill

Security audit

Drop Pick

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed commerce research workflow, but it also instructs agents to perform external store import and listing-event actions without a clear confirmation boundary.

Install only if you intend to use credentialed Alibaba/OpenCLI commerce tooling and are comfortable reviewing every platform action. Before running post-selection actions, require an explicit confirmation showing the exact account, product IDs, destination channel, and operation; also pin or verify plugin sources before installation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:63
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis
`. ``` ### Technical Analysis The skill instructs the agent to install plugins using only a short package name. It does not specify an exact version, immutable package digest, verified publisher, trusted registry, or signature-validation procedure. Consequently, the code installed during execution may differ from the dependency reviewed when this skill was audited. If the plugin registry, publisher account, package resolution mechanism, or one of the named packages is compromised, an attacker-controlled plugin could execute under the privileges of the `opencli` process. This is particularly sensitive because the skill declares and uses Alibaba API credentials, including `ALI_APP_KEY`, `ALI_APP_SECRET`, and `ALI_ACCESS_TOKEN`. A malicious plugin running in the same environment may be able to read these variables and access other files or credentials available to the process. ### Attack Path 1. An attacker compromises a plugin publisher or the package registry used by `opencli`, or publishes a package that is incorrectly resolved under one of the required names. 2. The agent runs `opencli plugin list` and determines that a required plugin is missing. 3. Following the skill instructions, the agent runs `opencli plugin install ` without pinning a version or validating the package origin and integrity. 4. The attacker-controlled plugin is installed and loaded by `opencli`. 5. The plugin executes with the local privileges of the agent process. 6. The malicious plugin reads available environment variables, including Alibaba credentials, or ac ...[truncated 820 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:377
Finding

Authenticated Commerce Mutations Lack Explicit Transaction Confirmation

Content
View full analysis
\ --event_type PRODUCT_LISTED --channel AMAZON -f json ``` Supported channels (`ecology_type`): `SHOPIFY`, `WIX`, `MERCADO`, etc. Supported event notification channels (`channel`): `SHOPIFY`, `AMAZON`, `TEMU`, `WALMART`, `SHEIN`, `MERCADO`, etc. ### Technical Analysis The skill's principal workflow is product-selection and sourcing analysis, which is predominantly read-only. The post-selection section extends that workflow with authenticated write operations that can import products into a commerce channel and report listing events to Alibaba. The instructions do not require transaction-specific confirmation immediately before executing these commands. They also do not require the agent to present the exact product IDs, destination channel, affected account, and expected effects for user review. These commands do not independently obtain additional privileges; they operate using permissions already granted to the configured credentials. However, the lack of an explicit confirmation boundary creates a risk that privileges intended for research or carefully supervised store management could be exercised unintentionally. ### Attack Path 1. A user invokes the skill for product research or product selection. 2. The agent completes the read-only research workflow and identifies candidate product IDs. 3. The ag ...[truncated 1304 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including buyer-channel-import in the quick-reference for a research skill normalizes use of a write-capable command that can push products into a merchant's store. This is dangerous because it broadens the effective permissions of the skill from analysis to external state changes, increasing the chance of accidental store modifications or abuse if the agent follows the documentation literally.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions can cause product data to be pushed directly into an external commerce platform and send listing status events, yet the skill does not present this as a high-risk side effect requiring explicit informed consent. In the context of a research skill, this is especially dangerous because users may not expect write actions against third-party accounts, leading to unintended listings, inventory sync issues, or commercial/account consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill for a very broad set of phrases, including generic requests like "product research," "what should I sell," and "any task involving evaluating products across supply and retail platforms." That scope is ambiguous and overlaps with common everyday e-commerce advice requests, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to write product-research/product-selection-report.md in the working directory without highlighting that this modifies local state. Silent file creation can surprise users, overwrite existing work, leak sensitive research into shared environments, or be misused in automated contexts where write operations were not expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as a product research and analysis tool, but it also includes operational commands to import products into external sales channels and send listing-event notifications. That creates a hidden capability boundary violation: a user invoking research could be led into actions that modify external systems, publish listings, or trigger downstream automation without a clearly separated workflow or explicit consent step.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.