Back to skill

Security audit

卖家精灵-流量关键词

Security checks for vulnerabilities and agentic risk

Overview

The skill provides the advertised ASIN keyword lookup, but it also adds account login, API-key creation, payment-order flows, persistent local storage, and automatic feedback reporting that deserve careful review before use.

Install only if you are comfortable letting this skill contact LinkFox/SellerSprite services with ASIN query data and API credentials. Avoid using the in-skill SMS login or payment flow unless you have verified the provider and destination URLs yourself; prefer obtaining keys directly from the official site. Treat generated API keys as secrets, do not paste them into shared transcripts, and review or clean the local linkfox cache/session folders if the query data is sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:99
Finding

Automatic External Feedback Submission Alters Agent Behavior and Can Disclose Conversation-Derived Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sellersprite_traffic_keyword.py:37
Finding

Environment-Controlled Network Destinations Can Receive API Keys and Login Tokens

Content
View full analysis
str: """Gateway base address: LINKFOX_TOOL_GATEWAY takes precedence.""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") def get_api_url(): sys.path.insert( 0, os.path.join( os.path.dirname(os.path.abspath(__file__)), "..", "..", "_shared", ), ) return get_api_base() + API_PATH def get_api_key(): key = ( os.environ.get("LINKFOX_AGENT_API_KEY") or os.environ.get("LINKFOXAGENT_API_KEY") ) if not key: print("API Key is not configured", file=sys.stderr) sys.exit(1) return key def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), } req = Request( api_url, data=data, headers=headers, method="POST", ) try: with urlopen(req, timeout=150) as response: return json.loads(response.read().decode("utf-8")) ``` Onboarding uses the same unsafe pattern for more sensitive account credentials: ```python def _login_base() -> str: return _env_base( "LINKFOX_LOGIN_API_URL", "https://api.linkfox.com", ) def _agent_user_base() -> str: re ...[truncated 2714 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/sellersprite_traffic_keyword.py:64
Finding

Keyword Requests Disclose Unnecessary Agent Session and Message Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.py:468
Finding

Onboarding Prints the Complete Reusable API Key to Standard Output

Content
View full analysis
dict: masked = _mask_phone(phone) if not re.fullmatch(r"\d{11}", phone): return { "error": f"login: invalid phone number: {phone}", "phone": masked, } if not re.fullmatch(r"\d{4,8}", code): return { "error": f"login: invalid verification code: {code}", "phone": masked, } lg = _login_v3(phone, code, channel) if "error" in lg: return {"error": lg["error"], "phone": masked} if lg.get("is_new_user"): lbt = _login_by_token(lg["access_token"], lg["refresh_token"]) if "error" in lbt: print(f"{TAG} {lbt['error']}", file=sys.stderr) info = _fetch_user_info_v3(lg["access_token"], lg["user_id"]) if "error" in info: return {"error": info["error"], "phone": masked} tok = _get_or_generate_api_token( lg["access_token"], lg["user_id"], info["group_id"], ) if "error" in tok: return {"error": tok["error"], "phone": masked} return { "api_key": tok["api_key"], "phone": masked, "group_id": info["group_id"], "member_id": info["member_id"], "source": tok["source"], "nick_name": lg.get("nick_name", ""), "team_name": info.get("team_name", ""), "is_new_user": lg.get("is_new_user", False), } def _emit(obj: dict) -> None: print(json.dumps(obj, ensure_ascii=False, indent=2)) def _cmd_login(args) -> int: r = login_and_get_key( args.phone.strip(), args.code.strip(), args.channel, ) _emit(r) if "api_key" in r: print( f"{TAG} successfully obtained API key " f"(source: {r['source']})", ...[truncated 1368 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sellersprite_traffic_keyword.py:250
Finding

Unsanitized SESSION_ID Allows Output-Path Escape

Content
View full analysis
str: """Prefer SESSION_ID; otherwise generate an identifier.""" env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _SESSION_CACHE: _SESSION_CACHE["_auto"] = ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) return _SESSION_CACHE["_auto"] def _ensure_session(ts: float) -> tuple[str, str]: """Return (linkfox_root, session_dir).""" date_str = time.strftime("%Y-%m-%d", time.localtime(ts)) sid = _session_id(ts) root = _linkfox_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _ensure_meta(root, session_dir, date_str, sid, ts) return root, session_dir ``` The onboarding script repeats the unsafe construction: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) path = os.path.join( _linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid, ) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_ID` is treated as a trusted directory name without rejecting: - Absolute paths. - `..` traversal components. - Forward or backward path separators. - Platform-specific drive or UNC syntax. - Symlink-mediated escapes. With `os.path.join`, an absolute final component can discard the previously constructed root. Traversal components can similarly resolve outside the intended date directory. The scripts subseq ...[truncated 1254 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sellersprite_traffic_keyword.py:210
Finding

Complete API Responses Are Stored with Weak File Protections and May Fall Back to a Shared Temporary Directory

Content
View full analysis
CACHE_TTL_SEC: return None try: with open(path, encoding="utf-8") as f: payload = json.load(f) if isinstance(payload, dict): payload.setdefault("_cache", {})["hit"] = True return payload except (OSError, json.JSONDecodeError): return None def _save_cache(path, payload): try: with open(path, "w", encoding="utf-8") as f: json.dump(payload, f, ensure_ascii=False, indent=2) except OSError: pass ``` The output-root selection explicitly permits a temporary-directory fallback: ```python candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) import tempfile candidates.append(os.path.join(tempfile.gettempdir(), "linkfox")) for root in candidates: try: os.makedirs(root, exist_ok=True) probe = os.path.join(root, ".write_probe") with open(probe, "w", encoding="utf-8") as f: f.write("") os.remove(probe) except OSError: continue root = os.path.abspath(root) _SESSION_CACHE["_root"] = root return root fall ...[truncated 2110 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:163
Finding

Onboarding Recommends Installing Unpinned Third-Party Dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = ( "Missing qrcode dependency; run: " "pip install qrcode pillow" ) print(f"{TAG} render_qr: {err}", file=sys.stderr) return { "png_path": None, "ascii_qr": None, "error": err, } ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError( "Missing requests dependency; run: pip install requests" ) ``` ### Technical Analysis The runtime instructions recommend installing `qrcode`, `pillow`, and `requests` without exact versions, hashes, a lockfile, or a specified trusted package index. As a result, the code reviewed during the audit is not sufficient to determine the code that will ultimately execute. Future package releases, a compromised registry, a malicious configured package index, or dependency substitution could introduce unreviewed code during installation or import. The package names are not obvious typographical substitutions, so this is an unsafe supply-chain practice rather than evidence that the current named packages are malicious. ### Attack Path 1. The onboarding environment lacks one of the dependencies. 2. The script instructs the user to run an unpinned `pip install` command. 3. pip resolves packages and transitive dependencies from the user's configured index. 4. A compromised or malicious package version is installed. 5. Package installation hooks or imported module code execute with the user's privileges. ### Impact Assessment A malicious dependency can execute arbitrary code with the privileges of the user running pip or the onboarding script. This may exp ...[truncated 293 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (26)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST target URL is derived from environment-controlled base URLs and is used to send highly sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys. If an attacker can influence the process environment, the script can be redirected to attacker-controlled infrastructure, causing credential exfiltration and account compromise.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway request URL is assembled from environment-controlled base configuration and invoked with the Authorization API key header. An attacker who controls the environment can redirect these requests to an arbitrary server and capture the API key as well as order/account metadata, enabling unauthorized API use and account abuse.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/sellersprite_traffic_keyword.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is ASIN traffic keyword lookup, but the detected behavior extends into authentication, account access, package selection, order creation, and payment initiation. This is dangerous because it crosses a clear trust boundary: a data-query skill could unexpectedly trigger identity, billing, or purchase workflows, exposing users to unauthorized charges, account misuse, or sensitive data handling they did not consent to.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

}

text

## Display Rules

1. 结果优先展示:关键词、自然位、广告位、流量占比类型、转化类型。
2. 明确标注查询周期(最近30天或历史月份)。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The onboarding document adds account recovery, registration, API-key setup, and billing/payment workflows that are outside the stated purpose of reverse-ASIN traffic keyword analysis. Expanding a narrow analytics skill into credential handling and purchase flows increases attack surface, can pressure users into sharing sensitive data, and creates opportunities for abuse if the script or surrounding process is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document instructs the agent to collect a user's phone number and drive SMS verification and login through a local script, which is not justified by the advertised analytics function. This creates unnecessary collection of personal data and enables credential/account actions through the skill, making phishing, account takeover assistance, or unauthorized registration easier if misused.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Documented plan listing, order creation, and payment guidance are unrelated to ASIN keyword analysis and allow the skill to facilitate purchases. Mixing analytics with commerce flows can be exploited for payment redirection, social engineering, or unauthorized charges, especially when the user is told to act on script-generated payment artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file implements a broad onboarding, authentication, billing, and payment workflow that is unrelated to the declared skill purpose of ASIN traffic-keyword lookup. Such scope mismatch is dangerous because users or reviewers may grant trust based on the benign manifest while the code actually collects credentials and facilitates account/payment operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can list purchasable plans, create orders, and generate payment QR codes despite the skill being presented as an analytical reverse-ASIN keyword tool. In this context, hidden billing capability materially increases risk of unauthorized purchases, deceptive behavior, and unexpected financial operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares capabilities that involve environment access, file writes, and network activity, but it does not explicitly scope or constrain those powers with a permissions or allowed-tools declaration. That makes the skill harder to audit and increases the chance that a caller invokes behavior with broader side effects than expected, especially since the skill also instructs writing full responses to disk and using environment variables for authentication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger logic is intentionally broad enough to activate even when SellerSprite is not mentioned, based only on a general ASIN keyword-analysis intent. Over-broad activation can route unrelated requests into a costly external workflow, cause unintended data disclosure to third-party services, and make it easier for adversarial phrasing to invoke the skill without informed user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language policy violations apply to all file types, including markdown. This file forces a specific language experience for users by presenting all instructions and field descriptions only in Chinese, with no opt-in, alternative language, or stated region-specific justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 174)May include surrounding context.

| page | integer | 第几页 | | position | integer | 总结果中排第几 |

curl 示例

bash
curl -X POST https://tool-gateway.linkfox.com/sellersprite/traffic/keyword   -H "Authorization: $LINKFOXAGENT_API_KEY"   -H "Content-Type: application/json"   -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown tells users to provide a phone number to a registration script without any privacy, retention, consent, or transmission safeguards. Even if the script is legitimate, collecting personal data in an undocumented way increases privacy risk and makes social-engineering collection of sensitive information appear normal within the skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs SMS-based login, token exchange, user/team discovery, and API token generation, which goes far beyond the stated read-oriented analytical scope. In context, this is especially dangerous because it enables credential harvesting and privilege acquisition under the cover of a seemingly harmless keyword-analysis skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language help and validation logic require an 11-digit domestic phone number and force area code +86, making the skill implicitly China-only. Because the file does not offer user opt-in or clearly justify the locale restriction as a region-specific tool, this is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The login and token-generation flow handles sensitive credentials and session artifacts, but this file provides no in-band warning, consent prompt, or disclosure about what is being transmitted and what token will be minted. In a misleadingly scoped skill, that omission increases the chance users expose credentials without understanding the security consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module documentation promises output is always written under the current working directory and explicitly forbids /tmp, but the implementation may silently fall back to ~/linkfox or the system temp directory when the preferred location is unavailable. This mismatch can cause sensitive API responses to be persisted in locations the user does not expect, weakening data-handling guarantees and potentially exposing data to other local users or processes depending on the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code sends the full JSON parameters plus SESSION_ID, MESSAGE_ID, MODE_ID, and APP_NAME headers to an external HTTPS endpoint. Although the module docstring describes output-file behavior, it does not disclose this outbound data transmission to users during execution, which is relevant to privacy and safety expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The activation and operational description is primarily in Chinese while some examples are in English, but there is no statement that the language should follow user preference or offer locale choice. This can create a language/locale policy issue if the skill implicitly defaults to Chinese behavior without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents a POST request to an external gateway and use of an Authorization header sourced from environment variables, but it does not include any warning that invoking the skill sends user-supplied query data and credentials to a remote service. For markdown files, missing warnings about behaviors affecting privacy or system integrity should be flagged when network transmission is described without disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill creates local directories and writes QR code PNG files under a session path, which affects the user's filesystem. While the command name mentions rendering a QR code, this file does not clearly warn users in help text or docstrings that a persistent image file will be created locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.