Back to skill

Security audit

闲鱼自动发布工具

Security checks for vulnerabilities and agentic risk

Overview

This skill automates live Xianyu account actions, but its scope, install path, and guardrails are not clear enough for a marketplace publishing tool.

Review this carefully before installing. Use it only in an isolated, non-shared environment and only with an account you are prepared to automate. Confirm every listing manually, avoid batch or scheduled posting unless you fully understand the effects, and clear any saved login session after use. The publisher should pin dependencies, align the runtime with the shipped code, document session storage, and add explicit confirmation before publishing or unpublishing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Package and Browser Binary Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a publishing tool, but the documented and inferred behavior extends into account login/session handling and broader account-item operations. That mismatch reduces informed user consent and can hide collection or use of persistent authenticated state, which is especially sensitive in browser automation tools interacting with a third-party marketplace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Broad trigger phrases like '发布闲鱼' or '自动上架' can cause the skill to activate in ambiguous contexts without clear user intent boundaries. For a tool that automates posting to a live marketplace, accidental invocation could lead to unwanted listings, account actions, or use of stored session state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that login state and cookies are saved locally, but it does not clearly disclose the security implications of persistent session storage. If these artifacts are stored insecurely or accessed by other local users/processes, an attacker may reuse the session to access or abuse the user's marketplace account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The publish() method performs a live marketplace publication immediately after being called, with no built-in confirmation, dry-run preview, or secondary approval gate. In an automation context, malformed inputs, prompt misuse, or unintended agent execution could cause irreversible or hard-to-recall listings to be posted to a real user account.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a publishing tool for posting goods, filling product info, uploading images, setting prices, and batch publishing. In addition to those expected publishing flows, the code can list existing products, fetch item details, unpublish items, and refresh exposure, which extends into inventory/account management rather than just publishing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The unpublish() method changes live account state by taking down a listing after only locating the item ID and clicking through the page flow, without any skill-level confirmation or guardrail. If invoked accidentally or by a confused upstream agent, it can disrupt sales, visibility, and inventory operations on the user's marketplace account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill’s natural-language interface and examples are entirely in Chinese, with no indication that users can choose another language or that the Chinese-only scope is intentional and justified. Under the policy, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CSV content uses Chinese descriptions and tags throughout, which indicates a fixed language/locale choice. For files of any type, this can be a natural-language policy issue when a skill or dataset enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.