Back to skill

Security audit

卖家精灵-市场统计

Security checks for vulnerabilities and agentic risk

Overview

The skill can fetch market statistics, but it also handles login, API keys, billing orders, feedback reporting, and local storage in ways users should review carefully.

Install only if you are comfortable with this skill using LinkFox credentials, collecting phone/SMS login data during onboarding, helping create payment orders, writing full results locally, and potentially sending feedback externally. Prefer manually obtaining and storing API keys in a secure secret manager, avoid endpoint override environment variables unless you trust the runtime, and review output/cache locations before using it with sensitive market research.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:78
Finding

Silent transmission of inferred user feedback

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.py:70
Finding

Environment-controlled endpoints can receive account credentials and access tokens

Content
View full analysis
str: for n in (name, *fallbacks): v = os.environ.get(n) if v: return v.rstrip("/") return default.rstrip("/") def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` The resulting destinations receive bearer credentials: ```python if access_token: h["authorization"] = access_token h["uid"] = _uid_header(access_token, user_id) if user_id else _LOGIN_FIXED_UID ``` ```python def _login_by_token(access_token: str, refresh_token: str) -> dict: resp = _http_post(f"{_agent_user_base()}/account/loginByToken", { "token": access_token, "refreshToken": refresh_token, "device": {"aid": "3026344186", "did": "", "type": "Windows", "os": "10", "model": "149.0.0.0", "brand": "Chrome"}, }, _headers("agent-linkfox-web", "agent.linkfox.com", access_token=access_token)) ``` ```python def _fetch_user_info_v3(access_token: str, user_id: str) -> dict: resp = _http_post(f"{_login_base()}/linkFoxApp/api/userCenter/userInfo", {}, _headers("agent-linkfox-web", "agent.linkfox.com", access_token=access_token, user_id=user_id)) ``` ```python def _get_or_generate_api_token(access_token: str, user_id: str, group_id: str) -> dict: hdr = _headers("agent-linkfox-web", "ai.linkfox.com", access_ ...[truncated 2138 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.py:484
Finding

API key is exposed through standard output and plaintext shell configuration

Content
View full analysis
None: print(json.dumps(obj, ensure_ascii=False, indent=2)) def _cmd_login(args) -> int: r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel) _emit(r) if "api_key" in r: print(f"{TAG} API key retrieved successfully", file=sys.stderr) return 0 return 1 ``` The onboarding documentation recommends permanent plaintext storage: ```shell setx LINKFOX_AGENT_API_KEY "" echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.zshrc && source ~/.zshrc echo 'export LINKFOX_AGENT_API_KEY=""' >> ~/.bashrc && source ~/.bashrc ``` ### Technical Analysis The onboarding command emits the full API key to standard output as JSON. In an Agent environment, standard output may be captured in conversation context, execution logs, CI logs, terminal scrollback, or orchestration telemetry. The documented configuration commands additionally place the key directly in shell startup files and may record it in shell command history. No restrictive file permissions, credential-store integration, redaction, or one-time secret channel is used. ### Attack Path 1. The user submits a phone number and SMS verification code through t ...[truncated 855 chars]
Remediation
View remediation

other

Warning
Location
scripts/sellersprite_market_statistics.py:60
Finding

Unnecessary session and message identifiers are transmitted with statistics requests

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:163
Finding

Onboarding recommends unpinned runtime dependency installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sellersprite_market_statistics.py:204
Finding

Complete API responses may be persisted to undocumented fallback locations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The code allows base URLs for login and agent-user API requests to be overridden from environment variables and then sends sensitive data to those URLs via requests.post. That data includes phone numbers, SMS codes, access tokens, refresh tokens, and generated API tokens, so a malicious or compromised runtime environment can redirect credentials to an attacker-controlled endpoint.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The gateway URL is derived from environment variables and used to build urllib requests that include the Authorization API key header. An attacker who can influence the environment can redirect these authenticated requests to an arbitrary server and capture the API key or manipulate plan/order responses.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The request destination and outbound metadata are partially controlled by environment variables: LINKFOX_TOOL_GATEWAY selects the base URL, and SESSION_ID/MESSAGE_ID/MODE_ID/APP_NAME are injected into headers before performing a network request. In an agent runtime where environment can be influenced by other components, this can exfiltrate sensitive operational metadata and the API key to an attacker-controlled endpoint via SSRF-style redirection.

Content

Scanner excerpt · scripts/sellersprite_market_statistics.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is market-statistics retrieval, but the skill behavior reportedly extends into login, API key generation, account/team info access, package listing, order creation, payment initiation, QR code generation, and payment-status polling. That is a major capability mismatch which can mislead users and reviewers, and it introduces access to account and payment workflows far outside the expected task boundary.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

}

text

## Display Rules

1. 明确展示统计口径:`topN`、`newProduct`、时间范围。
2. 先输出关键总览指标,再输出扩展字段。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The onboarding document introduces authentication recovery, scripted registration, and billing/payment handling that are unrelated to a market-statistics skill's stated purpose. This unnecessary expansion of scope can cause the agent to collect credentials or personal data and initiate account/payment flows, increasing the attack surface and enabling abuse well beyond reading market statistics.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS login, token retrieval, package listing, order creation, and payment QR generation, which is materially unrelated to the declared SellerSprite market-statistics function. This mismatch indicates hidden capability expansion and creates unnecessary access to user identities, credentials, and billing flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill can create orders, render payment QR codes, and query payment status despite the advertised purpose being market-statistics lookup. Embedding purchasing capability in an unrelated analytics skill increases the risk of deceptive monetization, unauthorized charges, and user confusion about what the skill actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation indicates capabilities to read environment variables, write files, and make network requests, but it does not declare any explicit tool scope or permission boundary. That creates an authorization gap where a broadly-triggered skill could access sensitive runtime context or persist data without clear user-facing limits.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text is intentionally broad, allowing the skill to trigger for general category-analysis requests even when the user does not mention SellerSprite. In combination with network, file-write, and other hidden behaviors, over-broad triggering increases the chance of unintended execution and unnecessary data exposure or charges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs autonomous submission of feedback to an external API whenever various conditions apply, including general praise, dissatisfaction, or anything improvable. This creates an unrelated outbound data flow that may transmit user interaction details without necessity for fulfilling the market-statistics function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says it will auto-detect and report feedback via a Feedback API, but the description does not warn users that aspects of their interaction may be transmitted externally. This undermines informed consent and may expose user content, sentiment, or workflow details beyond what is necessary for the requested market-statistics task.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 131)May include surrounding context.

| firstShelfDate | string | 商品首次上架日期 | | lastShelfDate | string | 商品最新上架日期 |

curl 示例

bash
curl -X POST https://tool-gateway.linkfox.com/sellersprite/market/statistics   -H "Authorization: $LINKFOXAGENT_API_KEY"   -H "Content-Type: application/json"   -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes a public feedback API that transmits free-form content externally, but it provides no warning about privacy implications, consent, or restrictions on including user data. In an agent/skill context, operators may inadvertently send sensitive prompts, outputs, or business data to a third-party endpoint, creating an avoidable data-leakage risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation directs the agent to support account registration and create payment orders, which is unjustified for a category market-statistics capability. In context, this makes the skill more dangerous because users invoking a harmless analytics feature could be steered into sensitive identity and payment operations they did not request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs collecting a user's phone number and SMS verification code for scripted registration without any explicit privacy notice, data minimization guidance, retention rules, or consent language. This exposes users to unnecessary handling of sensitive personal data and authentication factors through an analytics skill that has no clear need to process them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI help/messages are written in Chinese, and the code does not offer any locale or language selection for users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code performs SMS-based login, token exchange, team lookup, and API key generation, all beyond the declared analytics use case. These capabilities let the skill collect and mint credentials that could be abused for account takeover, unauthorized API access, or cross-context impersonation if the skill or environment is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill generates or retrieves an API token and returns it directly in command output without in-file safeguards or warnings about sensitive handling. In agent environments, stdout may be logged, surfaced to other components, or retained in transcripts, causing credential leakage and downstream unauthorized access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation promises that writing to /tmp is forbidden and that failure to write the current directory should error, but the code actually falls back to home and temporary directories automatically. This mismatch can cause sensitive output to be written to less secure or unexpected locations, defeating operator assumptions and potentially exposing data in shared temp storage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s stated purpose is a market-statistics query, but the implementation silently persists full API responses, cache entries, and session metadata to local storage by default. This creates an unexpected data-retention surface that may store proprietary query results, identifiers, and usage metadata longer than users or operators expect, increasing exposure to local disclosure and cross-session leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains natural-language instructions and behavior descriptions primarily in Chinese, including the module docstring and operational notes. Because the skill does not offer the user a language/locale choice or document a justified locale restriction, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.