Back to skill

Security audit

跨境电商选品工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ecommerce helper, but its web app has review-worthy security risks around network exposure, unsafe browser rendering, and unauthenticated billable AI use.

Review before installing or exposing this beyond a private local environment. Disable Flask debug by default, bind local development to localhost, restrict CORS, add authentication and rate/cost limits before using an OpenAI API key, sanitize all frontend rendering, and update or lock dependencies through one reviewed install path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
templates/index.html:469
Finding

DOM-Based Cross-Site Scripting Through Unescaped API and AI Output

Content
View full analysis

📈 ${d.keyword} 分析结果

${d.search_volume.toLocaleString()}
月搜索量
${(d.competition * 100).toFixed(0)}%
竞争度
${d.trend === 'rising' ? '📈' : d.trend === 'falling' ? '📉' : '➡️'} ${d.trend}
趋势
$${d.suggested_bid}
建议竞价

相关关键词

${d.related_keywords.map(k => `${k}`).join('')}
`; ``` The AI listing response is rendered through the same unsafe sink: ```javascript resultDiv.innerHTML = `

📝 产品标题

${d.title}

⚡ 5点描述

text
${d.short_description}

📋 完整描述

text
${d.full_description}

🏷️ 关键词

Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
app.py:244
Finding

Flask Debug Mode Enabled by Default on All Network Interfaces

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
app.py:10
Finding

Unauthenticated Billable AI Endpoint Exposed Through Permissive CORS

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:9
Finding

Setup Script Installs Mutable Unpinned Dependency Versions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (25)

Known Vulnerable Dependency: pymysql==1.1.0 — 2 advisory(ies): CVE-2024-36039 (PyMySQL SQL Injection vulnerability); CVE-2024-36039 (PyMySQL SQL Injection vulnerability)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

PyMySQL 1.1.0 is flagged with a critical SQL injection-related advisory. In any skill that connects to MySQL, a vulnerable database client or unsafe query construction path can result in unauthorized data access, modification, or complete database compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 68)May include surrounding context.

2. 配置环境变量 (可选)

bash
# 创建 .env 文件
cat > .env << EOF
FLASK_DEBUG=true
PORT=5000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

2. 配置环境变量 (可选)

bash
# 创建 .env 文件
cat > .env << EOF
FLASK_DEBUG=true
PORT=5000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

2. 配置环境变量 (可选)

bash
# 创建 .env 文件
cat > .env << EOF
FLASK_DEBUG=true
PORT=5000

Known Vulnerable Dependency: flask-cors==4.0.0 — 10 advisory(ies): CVE-2024-6866 (Flask-CORS vulnerable to Improper Handling of Case Sensitivity); CVE-2024-6839 (Flask-CORS improper regex path matching vulnerability); CVE-2024-1681 (flask-cors vulnerable to log injection when the log level is set to debug) +7 more

High
Category
Supply Chain
Confidence
99% confidence
Finding

Flask-CORS 4.0.0 is reported with multiple CORS-related vulnerabilities, including case-sensitivity and regex path matching issues. Because CORS controls browser-based cross-origin access, flaws here can allow unintended origins to access sensitive API responses or enable bypass of intended restrictions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: gunicorn==21.2.0 — 4 advisory(ies): CVE-2024-6827 (Gunicorn HTTP Request/Response Smuggling vulnerability); CVE-2024-1135 (Request smuggling leading to endpoint restriction bypass in Gunicorn); CVE-2024-6827 (Gunicorn HTTP Request/Response Smuggling vulnerability) +1 more

High
Category
Supply Chain
Confidence
99% confidence
Finding

Gunicorn 21.2.0 is flagged for request smuggling vulnerabilities. In a production web deployment behind proxies or load balancers, request smuggling can let attackers bypass security controls, poison request streams, or reach restricted endpoints unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents all user-facing instructions, headings, and examples in Chinese, which effectively forces a specific language for use of the skill. The policy allows locale or language constraints only when users are given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module description and user-facing strings throughout the file are written in Chinese, indicating the skill is effectively forcing a specific language. The policy allows locale constraints only when users can opt in or when the regional limitation is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flask==3.0.0 — 2 advisory(ies): CVE-2026-27205 (Flask session does not add `Vary: Cookie` header when accessed in some ways); CVE-2026-27205 (Flask is a web server gateway interface (WSGI) web application framework. In ver)

Medium
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is pinned to a Flask version flagged with a known advisory affecting session handling and cache variation behavior. In a web-facing skill, framework-level session and caching issues can lead to cross-user content exposure or weakened session isolation if the application uses Flask sessions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.31.0 — 6 advisory(ies): CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi); CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func) +3 more

Medium
Category
Supply Chain
Confidence
94% confidence
Finding

Requests 2.31.0 has several reported advisories including credential leakage via malicious URLs and session verification issues. If this skill makes outbound requests to user-influenced URLs or relies on persistent sessions, these flaws can expose secrets or weaken TLS verification guarantees.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: python-dotenv==1.0.0 — 2 advisory(ies): CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)

Medium
Category
Supply Chain
Confidence
90% confidence
Finding

python-dotenv 1.0.0 is associated with a symlink-following arbitrary file overwrite issue in set_key. If the skill or its tooling modifies .env files in environments where attackers can influence paths or symlinks, this can lead to overwriting sensitive files or privilege abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code transmits product_name, keyword_analysis, and competitor_data to a third-party OpenAI API without any consent check, minimization, classification, or disclosure mechanism. If those inputs contain proprietary business information, customer data, or sensitive market intelligence, this can cause unintended data exposure outside the local system and create privacy, confidentiality, or contractual compliance issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The public method docstring says it 'scrapes competitor data' and the class docstring says it is a competitor analysis service, while the actual implementation delegates to _generate_mock_competitors, which fabricates randomized products instead of retrieving real external data. This is an active contradiction in the code documentation, not merely an omitted detail, and it can mislead downstream users about the provenance and trustworthiness of the results.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file includes natural-language docstrings and comments only in Chinese, such as the module header, class docstring, and method documentation. That effectively forces a specific language for maintainers or agent surfaces consuming these strings, with no opt-in or stated region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing strings in this shell script, including the installation banner and usage instructions, are entirely in Chinese. This can violate language/locale policy when a skill implicitly forces one language without giving users an opt-in choice or stating that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document declares lang="zh-CN", and the visible UI text is predominantly in Chinese, which imposes a specific language/locale on users without any opt-in or language selection mechanism. This matches the policy concern for language or locale constraints that are not user-selectable or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description is presented entirely in Chinese and does not indicate any option for alternative languages or user language selection. Under the policy criteria, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language interface text entirely in Chinese, starting with the module docstring and continuing through the CLI experience. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy violation unless the tool is clearly documented as region-specific or offers a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The main CLI parser and subcommand help strings are presented only in Chinese, which constrains the user interface to one language. Because the file does not provide a language selection mechanism or an explicit locale-specific justification, this conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code file contains natural-language comments and docstrings entirely in Chinese, including labels such as '数据模型定义' and 'AI生成的Listing'. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The module comment on L01 is written only in Chinese ('服务模块'). This introduces a language-specific constraint in natural-language content without offering any user choice or documenting that the skill is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file's natural-language instructions and docstrings are in Chinese, but the generated listing templates and the OpenAI prompt force English-language output. This imposes a language choice without explicit user opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code uses Chinese natural-language comments and docstrings throughout, which indicates the skill is authored for a specific language audience without any visible user opt-in or documented locale restriction. Under the language/locale policy rule, forcing a specific language without choice can be a policy concern even when it appears only in inline documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file’s natural-language comments and docstrings are entirely in Chinese, including the service description and method documentation. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation when no justification or language choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.