Back to skill

Security audit

Taobao Product Research

Security checks for vulnerabilities and agentic risk

Overview

This Taobao scraping skill mostly does what it says, but it persists a logged-in browser profile and downloads marketplace-controlled image URLs with weak safeguards.

Review before installing. Use this only in an isolated workspace or account where persistent Taobao login data is acceptable, delete browser_data when finished, and avoid running it on networks where internal services are reachable. The publisher should add URL validation and download limits, document session storage more clearly, and update/pin dependencies before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/taobao_research.js:174
Finding

Unrestricted Product Image Fetching Enables Blind SSRF and Resource Exhaustion

Content
View full analysis
{ const protocol = url.startsWith('https') ? https : http; const file = fs.createWriteStream(filepath); protocol.get(url, (response) => { if (response.statusCode !== 200) { reject(new Error(`Failed to download: ${response.statusCode}`)); return; } response.pipe(file); file.on('finish', () => { file.close(); resolve(filepath); }); }).on('error', reject); }); } ``` ```javascript // scripts/taobao_research.js:249-256 const p = products[i]; if (p.image) { try { const ext = p.image.match(/\.(jpg|jpeg|png|gif)/i)?.[0] || '.jpg'; const imgPath = path.join(imageDir, `img_${i+1}${ext}`); await this.downloadImage(p.image, imgPath); p.localImage = imgPath; ``` ### Technical Analysis The image URL is extracted from marketplace-controlled page content and passed directly to Node.js `http.get` or `https.get`. The implementation does not parse and validate the URL, restrict destination hostnames, resolve and reject private or loopback addresses, impose request timeouts, limit response size, or verify that the response is an authentic supported image. The protocol decision only checks whether the string starts with `https`; all other nonempty values are handed to the HTTP client. A malicious or compromised product listing could th ...[truncated 2326 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins axios 1.13.6, and the reported advisories include SSRF- and prototype-pollution-related issues that can materially affect software making outbound HTTP requests. This skill’s purpose is large-scale web data collection from Taobao and likely processes URLs, redirects, proxy settings, and remote content, which makes HTTP client flaws more relevant than in an offline-only tool.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

brace-expansion 1.1.12 is reported with multiple denial-of-service issues involving pathological expansion patterns. In a package-lock this is a transitive dependency and not necessarily directly reachable from attacker-controlled input, but if any glob or pattern processing path consumes untrusted strings, it could cause excessive CPU or memory use.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names/filenames. In this skill context, risk depends on whether multipart requests are ever built from untrusted input; if they are, crafted names could corrupt request structure or smuggle unintended headers/content.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

brace-expansion 2.0.2 has the same family of DoS issues as the older 1.x line. As a transitive package this is mostly a supply-chain hygiene and availability concern, but it becomes exploitable if untrusted pattern strings can reach archive, glob, or file matching features.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: tmp==0.2.5 — 1 advisory(ies): CVE-2026-44705 (tmp has Path Traversal via unsanitized prefix/postfix that enables directory esc)

High
Category
Supply Chain
Confidence
80% confidence
Finding

tmp 0.2.5 is flagged for path traversal via unsanitized prefix/postfix values, which can enable file creation outside intended temporary directories. Because this skill generates Excel reports and may write images/files, unsafe temp-file handling could affect local file integrity if attacker-controlled names flow into temp path generation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The file permits installation of a vulnerable Axios version with multiple advisories, including SSRF/proxy bypass and prototype-pollution-related man-in-the-middle or credential-theft scenarios. In a product-research skill that makes outbound web requests and may operate in environments with proxies or internal network reachability, such flaws are more dangerous because they can be leveraged to redirect requests, access unintended hosts, or compromise request/response integrity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is broad enough to activate on generic product-research or ecommerce-information requests without clearly signaling that the skill will perform Taobao-specific automated scraping and data collection. This can cause unintended invocation of a browser-automation workflow that collects external data, downloads images, and writes local files when the user may have expected a lighter-weight or different tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that Taobao login state is saved in a local browser_data directory, but the description does not prominently warn users about persistent credential/session storage or its security implications. Stored authenticated browser state can be reused by other local processes or users on the same machine, increasing the risk of account misuse, session theft, or unintended access to the user's Taobao account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language interface, examples, prompts, and status messages are written exclusively in Chinese, which effectively constrains users to a specific language. There is no opt-in, alternate locale handling, or documentation that this is intentionally limited to a China-specific or Chinese-only audience.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. This scraper interacts with remote sites and could follow redirects during HTTP fetching, so if any authenticated requests or sensitive headers are used, credential leakage to an attacker-controlled redirect target is possible.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==8.3.2 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
70% confidence
Finding

uuid 8.3.2 is reported to lack buffer bounds checks in specific generation modes when a buffer argument is supplied. This is a lower-severity issue and may not be reachable in this skill at all, but it still represents unnecessary exposure from an outdated transitive dependency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The package description is written only in Chinese ("淘宝产品调研和数据采集工具"), which signals a language-specific skill presentation without any indication that users can choose another language. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Using a caret version for Playwright allows future minor/patch releases to be installed automatically, which can introduce unreviewed code changes and supply-chain risk. In an automation-heavy scraping skill, dependency behavior changes can materially affect browser control, network access, and execution reliability.

Content

Scanner excerpt · scripts/package.json (reported line 7)May include surrounding context.

json
"description": "淘宝产品调研和数据采集工具",
  "main": "taobao_research.js",
  "dependencies": {
    "playwright": "^1.40.0",
    "exceljs": "^4.4.0",
    "axios": "^1.6.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Using a caret version for ExcelJS permits automatic upgrades to versions that have not been explicitly reviewed. While lower risk than browser/network libraries, this still creates supply-chain exposure and could affect file generation logic or introduce malicious or vulnerable transitive code.

Content

Scanner excerpt · scripts/package.json (reported line 8)May include surrounding context.

json
"main": "taobao_research.js",
  "dependencies": {
    "playwright": "^1.40.0",
    "exceljs": "^4.4.0",
    "axios": "^1.6.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using a caret version for Axios creates supply-chain risk and, in this case, is especially dangerous because the dependency is also flagged as having known vulnerabilities. Since this skill performs web data collection, an HTTP client issue can directly affect outbound requests, proxy handling, credential safety, and response trust.

Content

Scanner excerpt · scripts/package.json (reported line 9)May include surrounding context.

json
"dependencies": {
    "playwright": "^1.40.0",
    "exceljs": "^4.4.0",
    "axios": "^1.6.0"
  }
}

Static analysis

No suspicious patterns detected.