Back to skill

Security audit

1688-以图搜图

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform 1688 image search, but it also adds sensitive account, payment, upload, local-retention, and automatic feedback behavior that needs review before installation.

Install only if you are comfortable giving this skill LinkFox credentials, allowing it to upload local images to public URLs, saving full responses locally, and using the bundled auth/billing flows. Avoid sharing SMS codes or payment actions through the skill unless you initiated them, and do not set custom LINKFOX_* endpoint environment variables unless you trust the destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:231
Finding

Automatic Disclosure of User Statements and Inferred Intent to a Feedback Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/alibaba1688_image_search.py:38
Finding

Credential-Bearing Requests Can Be Redirected to Environment-Controlled Hosts

Content
View full analysis
str: """Gateway base URL: environment override, otherwise production.""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), } req = Request( api_url, data=data, headers=headers, method="POST", ) ``` From the uploader: ```python _API_BASE = ( os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com" ).rstrip("/") PRESIGN_URL = f"{_API_BASE}/oss/file/presignedPut" ``` From onboarding: ```python def _agent_base() -> str: return _env_base( "LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY" ) def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base( "LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com" ) ``` Credential attachment is performed as follows: ```python if access_token: h["authorization"] = access_token h["uid"] = _uid_header(access_token, user_id) if user_id els ...[truncated 1948 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/alibaba1688_image_search.py:253
Finding

Unsanitized Session Identifier Allows Output-Path Traversal

Content
View full analysis
str: """Prefer SESSION_ID; otherwise generate a process-stable identifier.""" env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _SESSION_CACHE: _SESSION_CACHE["_auto"] = ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) return _SESSION_CACHE["_auto"] def _ensure_session(ts: float) -> tuple[str, str]: date_str = time.strftime("%Y-%m-%d", time.localtime(ts)) sid = _session_id(ts) root = _linkfox_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _ensure_meta(root, session_dir, date_str, sid, ts) return root, session_dir ``` From onboarding: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) path = os.path.join( _linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid ) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_ID` is used directly as a path component. There is no rejection of: - `..` traversal components. - Absolute paths. - Path separators. - Platform-specific drive or UNC paths. - Symbolic-link traversal. With `os.path.join`, an absolute final component can discard preceding path components on supported platforms. Relative traversal components can escape the intended date and LinkFox directories after path normalization. The search flow writes JSON responses and metadata into the resulting locat ...[truncated 1336 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_image.py:92
Finding

Public Image Upload Accepts Extension-Disguised Content and Unvalidated Upload Destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onboarding.py:488
Finding

Generated API Key Is Exposed Through Standard Output and Shell Configuration Instructions

Content
View full analysis
int: r = login_and_get_key( args.phone.strip(), args.code.strip(), args.channel ) _emit(r) if "api_key" in r: print( f"{TAG} Successfully obtained API key " f"(source: {r['source']})", file=sys.stderr ) return 0 return 1 ``` The onboarding documentation then directs the Agent to relay the key and embed it into shell configuration commands: ```bash setx LINKFOX_AGENT_API_KEY "" echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.zshrc echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.bashrc ``` ### Technical Analysis The generated API key is serialized as plaintext JSON to stdout. In an Agent environment, stdout may be retained in tool logs, conversation transcripts, CI records, terminal scrollback, or execution telemetry. The documented shell commands also place the key directly into command text. This can expose it through conversation history, shell history, process monitoring, terminal logging, backups, and profile files. The script does not verify restrictive permissions on the destination shell profile. Although a user needs a way to configure the generated key, exposing it through routine Agent output and command history is not a safe secret-distribution mec ...[truncated 886 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:166
Finding

Runtime Instructions Recommend Installing Unpinned Third-Party Dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = "Missing qrcode dependency; run: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return { "png_path": None, "ascii_qr": None, "error": err } ``` The HTTP path similarly recommends an unpinned package: ```python def _require_requests() -> None: if requests is None: raise RuntimeError( "Missing requests dependency; run: pip install requests" ) ``` ### Technical Analysis The Skill instructs users to install packages by name without: - Exact versions. - Cryptographic hashes. - A lockfile. - An isolated environment. - A specified trusted package index. - A reviewed dependency manifest. This does not prove that the named packages are currently malicious. However, it delegates future code selection to mutable package-index state and can install versions different from those reviewed during the Skill audit. Because Python packages execute installation and runtime code with the user's privileges, a compromised release, dependency takeover, malicious index configuration, or incompatible future release can affect the Skill host. ### Attack Path 1. A user invokes onboarding in an environment missing `requests`, `qrcode`, or `Pillow`. 2. The script instructs the user to run an unpinned `pip install` command. 3. Package resolution uses the environment's configured index and selects the latest matching distributions. 4. A compromised, substituted, or unexpectedly changed package is installed. 5. Package installation hooks or imported runtime code execute ...[truncated 632 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (33)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request destination is influenced by environment-controlled configuration via LINKFOX_TOOL_GATEWAY, and the same request carries the API key plus session/app metadata in headers. In environments where untrusted users, wrappers, or prior steps can set environment variables, this enables credential and metadata exfiltration to an attacker-controlled endpoint through a legitimate outbound POST.

Content

Scanner excerpt · scripts/alibaba1688_image_search.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST target URL is derived from environment-controlled base URLs, and this function sends sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect authentication traffic to attacker-controlled infrastructure and capture credentials and tokens.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request uses a URL built from environment-controlled base configuration and attaches the LinkFox API key in the Authorization header. If the environment is tampered with, the skill can be induced to transmit the API key and account/order operations to an attacker-controlled endpoint, enabling credential theft and abuse of the user's account.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 57, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/upload_image.py (reported line 73)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'req' from os.environ.get (line 57, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/upload_image.py (reported line 106)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=120) as response:
            if response.status not in (200, 201):
                print(f"Upload failed with status: {response.status}", file=sys.stderr)
                sys.exit(1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as consuming an image URL for 1688 product search, but the finding indicates it instead uploads local files to external storage and may not perform the advertised marketplace query at all. This is risky because users may provide data believing it will be used only for search, while the skill performs undeclared data transfer and file-handling operations with different privacy and security implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as consuming an image URL for 1688 product search, but the finding indicates it instead uploads local files to external storage and may not perform the advertised marketplace query at all. This is risky because users may provide data believing it will be used only for search, while the skill performs undeclared data transfer and file-handling operations with different privacy and security implications.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

在1688搜索与图片相似的商品,图片地址为 https://example.com/product.jpg,价格区间10-100元

text

## Display Rules

1. **Present data clearly**: Show results in a structured table with key columns: product image, title, price, dropship price, monthly sales, minimum order quantity, repurchase rate, and seller identity
2. **Image display**: When the response includes imageUrl for products, display them inline for visual comparison

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The onboarding documentation introduces account recovery, registration, and billing workflows that are materially outside the declared purpose of an image-search skill. This expands the skill from product lookup into credential handling and payment orchestration, creating unnecessary access to sensitive user data and increasing the chance of social-engineering, unauthorized account actions, or abuse of the agent as a payment intermediary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document explicitly authorizes collecting a user's phone number and processing SMS verification-code login for a skill that only needs to search products by image. Handling phone numbers and one-time codes gives the skill power to access or create accounts on behalf of users, which is highly sensitive and unnecessary for the stated functionality.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The billing instructions let the skill list subscription plans, create payment orders, and check payment status, none of which are required for image-based supplier search. Embedding payment handling into a non-payment skill increases phishing and financial-abuse risk by normalizing in-chat plan selection and payment initiation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API-key retrieval, package listing, and purchasing flows, which are unrelated to the declared 1688 image-search purpose. This mismatch materially increases risk because the skill requests and processes sensitive credentials and payment operations outside the user's likely expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Embedding order creation, payment QR generation, and order-status querying inside an image-search skill grants the code the ability to initiate billing-related actions that users would not reasonably expect from this capability. In context, this is more dangerous because the declared skill domain does not justify charging behavior, making deceptive or unauthorized purchases more plausible.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section performs SMS verification, login, team discovery, and API-token generation/disclosure, none of which are necessary for searching 1688 by image. In this skill context, collecting phone-based auth factors and issuing API keys is especially risky because it enables credential harvesting and persistent account access under the guise of unrelated functionality.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope while its documented behavior requires environment access, filesystem writes, and network calls. In an agent setting, missing scope boundaries can let a seemingly simple search skill invoke broader capabilities than users or reviewers expect, increasing the chance of unauthorized data access or unintended side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims live results are not stored, yet it instructs the system to always persist the full API response to local JSON files. This inconsistency creates a data-retention risk because user-provided images, search terms, supplier data, and possibly account metadata may be stored longer than users expect.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Always writing full API responses into session-scoped files in the project directory creates persistent local copies of user-related data and search results. In shared workspaces or repos, these files may be accidentally exposed, indexed, committed, or read by other tools, extending the attack surface beyond the immediate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs uploading a local image to obtain a public URL but does not require a prominent privacy warning or explicit consent before making the file publicly accessible. This can expose sensitive local files, embedded metadata, or proprietary product images to anyone with the link, which is especially risky in sourcing and business workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatic feedback reporting is unrelated to the core 1688 image-search function and introduces an extra outbound data flow. If triggered silently, it can transmit user content, error details, or behavioral signals to another endpoint without clear necessity or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates automatic feedback reporting without user opt-in, creating a silent secondary use of interaction data. In practice this can leak user queries, dissatisfaction statements, or operational details to another service beyond the primary requested function.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 155)May include surrounding context.

}

text

## curl 示例

### 基础以图搜图

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents a separate feedback-posting API that is unrelated to the core 1688 image-search function. In an agent skill context, this expands the skill’s effective capability surface and can enable unsolicited transmission of user-derived content to another external service, especially if an agent treats all documented endpoints as approved actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The feedback API accepts free-form content and sends it to a different external endpoint, but the documentation does not warn that user text may be transmitted off-platform for a secondary purpose. This creates a privacy and prompt-scope risk because agents may forward sensitive user statements, business context, or conversation summaries without explicit notice or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire onboarding guidance is written as mandatory Chinese-language operational instructions, including phrases like '转发给用户' and '透传给用户即可', but it does not offer an alternative language or state that the skill is intended only for Chinese-speaking users. This creates a natural-language locale policy concern because it implicitly forces a specific language for user interactions without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.