T09 · Insecure Skill Coding Practices
- Location
scripts/track_product.py:45- Finding
Untrusted search content is embedded directly into an LLM instruction
- Content
View full analysis
List[Dict]: """Search product prices via SkillBoss API Hub (web search + LLM extraction).""" # Step 1: web search for product listing on platform search_result = pilot({ "type": "search", "inputs": {"query": f"site:{platform}.com {keyword} price buy"}, "prefer": "balanced", }) search_data = search_result["result"] # Step 2: LLM extracts structured price data from search results extract_result = pilot({ "type": "chat", "inputs": { "messages": [ { "role": "user", "content": ( f"From these search results, extract the current price for '{keyword}' on {platform}. " f"Return ONLY a valid JSON object with these fields: " f'{{\"title\": string, \"price\": number, \"seller\": string, \"rating\": number, \"condition\": string}}. ' f"Search results: {str(search_data)[:3000]}" ), } ] }, "prefer": "balanced", }) ``` ### Technical Analysis Search-result content controlled by marketplace pages, sellers, or other indexed third parties is concatenated directly into the same LLM message as the trusted extraction instruction. There is no strong separation between instructions and untrusted data. A malicious listing can contain prompt-like text directing the model to ignore the extraction request and return attacker-selected values. The subsequent regular-expression and JSON parsing logic verifies only that the response resembles a JSON object; it does not verify that the price, seller, rating, condition, or title is supported by ...[truncated 1348 chars]- Remediation
View remediation
