Back to skill

Security audit

Add to Cart (Multi-Platform)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a shopping-account automation tool, but it handles logged-in browser sessions in unsafe and under-scoped ways that need review before use.

Review this before installing. Use it only in a dedicated Brave profile/tab with accounts you are comfortable automating, avoid attacker-supplied search terms or detail URLs, and require explicit confirmation before any cart, favorite, wanted, or chat action. The token-based Taobao flow and unsafe interpolation patterns should be fixed before normal use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/add_to_cart.sh:202
Finding

Arbitrary Local Command Execution Through Python Source Injection

Content
View full analysis
/dev/null || \ python3 -c "import urllib.parse, sys; print(urllib.parse.quote(sys.argv[1]))" "$raw" } ``` ### Technical Analysis The `url_encode` function places the user-supplied product keyword directly inside a Python program passed to `python3 -c`. Shell quoting does not make the generated Python source safe. A keyword containing a single quote can terminate the Python string and append additional Python statements. For example, an input shaped like the following breaks out of the intended call: ```text '); __import__("os").system(""); # ``` The injected statement is evaluated by the first `python3 -c` invocation. The safe-looking fallback does not mitigate this issue because it only executes if the vulnerable command fails, and injected code may already have run successfully. ### Attack Path 1. An attacker supplies or persuades a user to use a crafted product-search keyword. 2. The script assigns that keyword to `KEYWORD`. 3. `url_encode "$KEYWORD"` passes it to the `raw` local variable. 4. The value is expanded into the source string given to `python3 -c`. 5. A single quote terminates the intended Python string. 6. Attacker-provided Python statements execute with the privileges of the user running the Skill. ### Impact Assessment Successful exploitation provides arbitrary local command execution under the current operating-system user account. Depending on that account's permissions, an attacker could: - Read or modify files accessible to the user. - Access local application configuration and credentials. - Make arbitrary network requests. - Alter other user-owned ...[truncated 260 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/add_to_cart.sh:60
Finding

Arbitrary JavaScript Execution in an Authenticated Browser Through Unsafe URL Interpolation

Content
View full analysis
&1 } ``` The Pinduoduo favorite mode incorporates an unvalidated product ID: ```bash if [[ "$PLATFORM" == "pdd-fav" ]]; then # 拼多多收藏模式: ./add_to_cart.sh pdd-fav GOODS_ID="$KEYWORD" URL="https://mobile.yangkeduo.com/goods1.html?goods_id=${GOODS_ID}" ``` The detail mode accepts an arbitrary URL and sends it to the vulnerable navigation function: ```bash if [[ "$PLATFORM" == "detail" ]]; then # 导航到商品详情页模式: ./add_to_cart.sh detail DETAIL_PLATFORM="$KEYWORD" DETAIL_URL="${3:-}" if [[ -z "$DETAIL_URL" ]]; then echo "❌ 缺少商品详情页URL" exit 1 fi URL="$DETAIL_URL" PLATFORM="$DETAIL_PLATFORM" ``` ```bash TAB_ID=$(get_tab_id) echo "📌 使用 tab: $TAB_ID" navigate_to_url "$URL" "$TAB_ID" ``` ### Technical Analysis `navigate_to_url` embeds `target_url` between single quotes in a JavaScript expression passed to the external CDP evaluator. Neither JavaScript escaping nor structured argument serialization is applied. A URL or product ID containing a single quote can close the intended string, append JavaScript statements, and comment out the remainder. The resulting code executes in the currently selected browser tab before navigation. Because the Skill is explicitly designed to operate a browser containing authenticated commerce sessions, injected JavaScript may execute in a sensitive authenticated origin. The `detail` platform parameter does not constrain the URL. There is no validation of the ...[truncated 1734 chars]
Remediation
View remediation
&1 } ``` Apply strict input validation as defense in depth: 1. Require `GOODS_ID` to contain digits only: ```bash [[ "$GOODS_ID" =~ ^[0-9]+$ ]] || { echo "Invalid product ID" >&2 exit 1 } ``` 2. Parse detail URLs with a standard URL parser. 3. Permit only the `https` scheme. 4. Enforce a hostname allowlist tied to the selected platform, such as the expected Taobao, Tmall, JD, Pinduoduo, or Goofish domains. 5. Reject URLs containing credentials, control characters, malformed hosts, or unsupported ports. 6. Do not automatically select the first available tab. Select or create a dedicated automation tab to reduce exposure of unrelated authenticated pages. 7. Add tests covering quotes, backslashes, newlines, semicolons, comment tokens, `javascript:` URLs, and deceptive hostname suffixes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

描述将该技能表述为“多平台电商加购物车/收藏自动化工具”,并具体声称可在淘宝/京东加购、拼多多收藏、闲鱼标记想要。代码中,只有拼多多 pdd-fav 分支真正执行了页面按钮点击来收藏商品,并做了简单验证。detail 分支只是导航到详情页。默认分支对淘宝、京东、拼多多、闲鱼仅构造搜索 URL、打开搜索页、等待、提取页面文本并输出“下一步”提示,明确说明加购/收藏需后续根据实际页面调整选择器,说明这些自动化动作并未在本代码中实现。因此,代码实际行为明显弱于且不同于声明的核心能力。未发现支付、下单、价格比较、推荐或订单管理等额外越权能力;问题在于声明夸大了自动化能力范围。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions explicitly extract _tb_token_ from cookies and use it to call a cart API, but provide no privacy or security warning around handling authenticated session material. Even if used in-browser, normalizing token extraction as an automation step increases the risk of session misuse, accidental logging, or adaptation of the pattern for broader authenticated actions beyond add-to-cart.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents browser automation that depends on networked interactions with remote e-commerce sites and authenticated sessions, but it does not declare any explicit tool scope or permissions boundary. That makes the capability surface less transparent to reviewers and increases the chance the skill will be run with broader access than intended, especially since it operates against live logged-in accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly requires users to be logged into multiple e-commerce platforms, which exposes account data, order history, addresses, and other sensitive session-linked content to the automation environment. Without a privacy warning, consent flow, or data-handling limits, the skill normalizes operating on high-value authenticated sessions without telling users what account data may be observed or mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions describe extracting the Taobao _tb_token_ from cookies and using it to perform a direct authenticated cart API request. Even if intended for legitimate automation, this handles session-derived authentication material and performs account actions outside normal UI controls, which raises the risk of credential misuse, token leakage, and unauthorized actions if logs, prompts, or tooling capture the token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide instructs operators to add items to cart, favorite products, or mark 'want' without an explicit warning that these actions modify the user's account state. Even though payment is excluded, these are still persistent account changes that can affect recommendations, seller interactions, saved lists, and shopping workflow, so lack of consent/notice is a meaningful safety issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Xianyu fallback selector includes button[class*="chat"], which can trigger a messaging/chat action rather than the stated limited action of marking an item as 'want'. That expands the skill's effective capability from low-risk wishlist automation into user-to-seller communication, creating unintended account activity and possible social-engineering or spam side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document enumerates selectors for account-affecting controls across multiple platforms, including add-to-cart, favorite, and want actions, but does not clearly warn that using them will modify the user's account state. Given this skill's purpose is live browser automation on logged-in commerce accounts, the lack of an explicit state-change warning increases the risk of accidental or unauthorized actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section provides directly executable DOM-click examples that can trigger live state-changing actions on e-commerce sites, including adding items to cart. In the context of a browser automation skill, such examples lower the barrier to unsafe automation and can cause unintended account-affecting actions if reused without confirmation gates.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

文件头注释宣称这是“多平台搜索 + 加购物车/收藏脚本”,并强调“不涉及支付,只做到加购物车/收藏为止”。但代码中唯一实际执行的写操作只有 L112-L173 的拼多多“收藏”;其余平台仅构造搜索 URL、导航页面并输出搜索结果,L324-L330 甚至提示用户后续需自行用其他步骤进入详情页并点击按钮。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The header, usage text, warnings, and all subsequent user-facing messages are written only in Chinese, which imposes a specific language on users. The file does not provide any opt-in, alternative locale, or documentation that this skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

L013 的注释明确表示脚本会执行到“加购物车/收藏为止”,给出已完成终态的意图;然而主流程 L302-L330 仅打开搜索页、提取文本并提示用户‘下一步’自行进入详情页、选择规格和点击加入购物车/收藏按钮。该注释与实际主路径行为相矛盾,而非仅仅信息不完整。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written only in Chinese ("多平台加购物车/收藏工具"), which implies a fixed language presentation with no indication that users can choose their preferred language or locale. Under the policy, language constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest limits the skill to adding items to cart, favoriting, or marking 'want', and explicitly excludes broader shopping actions. Line L086 documents a selector for a '领券按钮' (coupon button), which is not justified by that stated purpose and suggests support for promotional actions outside the declared workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.