T09 · Insecure Skill Coding Practices
- Location
scripts/colipu_order.py:103- Finding
Financial orders can be submitted without mandatory user confirmation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real Colipu procurement helper, but some shipped paths can place business orders without the confirmation the skill promises.
Review before installing. Use only with a Colipu account whose purchasing authority you are willing to expose to this skill, avoid `colipu_order.py`, `colipu_search.place_order()`, and `quick_order()` until they enforce a final per-order confirmation, set strict quantity and budget limits externally, and do not log or share passwords, cookies, full request bodies, full responses, addresses, or order details unless redacted.
scripts/colipu_order.py:103Financial orders can be submitted without mandatory user confirmation
scripts/colipu_order.py:39Unvalidated order quantities can cause excessive or malformed purchases
scripts/colipu_client.py:469Authentication session material is disclosed in terminal and automation logs
scripts/colipu_client.py:88Network requests lack bounded connection and read timeouts
The declared description presents a full procurement assistant supporting the entire flow: product search, placing orders, viewing order details, querying orders, and canceling orders. The supplied code chunk implements only one part of that scope: placing an order for explicitly provided item IDs and quantities. It logs in, looks up product details, chooses the first receiver and cost center, pre-creates and confirms the order, and prints success/failure information. There is no implementation here for searching products generally, retrieving existing order details, listing/querying orders, or canceling orders. While a single file may represent only part of a larger skill, based on this chunk alone the behavior is materially narrower than the declared end-to-end assistant capability, so this should be flagged as a mismatch.
该代码块的实际功能集中在商品搜索与下单,且会使用账号密码登录并调用收货人、成本中心、预下单和确认下单相关接口。这与声明中的“商品搜索、下单”部分一致,但声明强调覆盖“订单详情、订单查询、取消订单全流程”,而本代码块中没有对应实现,因此存在描述大于实际行为的能力不匹配。未发现额外的高风险未声明能力;问题主要是声明的功能范围明显超出此代码块实际提供的能力。
os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.
from colipu_client import ColipuClient
if os.name == "nt":
os.system("chcp 65001 >nul 2>&1")
def _err(msg):
print(f"\n[X] {msg}\n")
The script proceeds from pre-submission directly to order confirmation without any interactive confirmation gate, dry-run mode, or explicit user acknowledgment. In a procurement skill, this can cause unauthorized or accidental purchases, especially if invoked by an agent pipeline that passes user intent ambiguously or with manipulated arguments.
The function executes confirm_order directly, which is a destructive external action that can create real purchase orders, yet there is no in-function approval check, confirmation prompt, or caller-supplied signed intent. In the context of a B2B purchasing skill, this is especially dangerous because accidental invocation, prompt confusion, or misuse of the tool can commit organizational funds and route goods to default recipients or cost centers.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
⚠️
client.quick_order(...)会跳过用户确认环节,仅供自动化测试 / 内部脚本,正式 Agent 流程不要直接使用。
# 1. 登录
The skill documents use of environment variables, shell commands, and direct network/API access, but it does not declare any explicit tool scope or allowed-tools boundaries. Without least-privilege restrictions, an agent runtime may grant broader capabilities than necessary, increasing the blast radius if the skill is mis-triggered, misused, or prompt-injected.
The trigger language is broad enough to activate on common procurement-related phrasing, including generic mentions of buying or calling the Colipu API. In a skill with purchasing and cancellation capabilities, overbroad triggering increases the chance of unintended invocation and action on ambiguous user intent.
The skill relies on session-cookie authentication via EGG_SESS and repeatedly instructs the agent to carry that cookie across requests. While session reuse is normal, documenting session persistence without explicit storage, lifetime, redaction, and non-logging controls creates risk of token leakage or misuse if the agent stores, echoes, or forwards the cookie improperly.
|---|------|------|------|-------------|
| 1 | `/api/vip/login` | POST | 账号密码登录 | 响应头 `Set-Cookie.EGG_SESS`、`Data.customerId` |
| 2 | `/api/b2bSearchApi/SearchByKeyWord` | POST | 关键词搜索商品 | `Data[].ItemId`、`Data[].SalePrice`、`Data[].ItemFullName` |
| 3 | `/api/b2bApi/GetAttributeGroupList` | GET | 商品详情(属性、起订量等) | `Data[].AttributeList`、`Data[].ItemAtte` |
| 4 | `/api/accountApi/receiver/list/0` | GET | 收货地址列表 | `[].ReceiverId`、`[].Status==A` |
| 5 | `/api/crm/getConcenter?IsGroupPower=N` | GET | 成本中心列表 | `Data[].CostCenterId`、`Data[].Status==A` |
| 6 | `/api/confirm/create` | POST | 预提交订单(拿 GuId) | `Data.Success`、`Data.Message`(=GuId) |
The markdown includes an order-cancellation operation but does not define a mandatory explicit user confirmation step analogous to the one required for order placement. Cancellation is a destructive business action, and omission of a hard confirmation control raises the risk of accidental or socially engineered order cancellation.
The skill instructs the agent to help compose support emails containing account identifiers plus request/response bodies and reproduction data. Even though it mentions desensitization in one section, the surrounding guidance still encourages disclosure of sensitive operational and transaction data in natural-language communications, which can leak personal, account, or commercial information outside the system boundary.
Telling the agent to include account details and full API request/response content in support emails creates a clear risk of exfiltrating sensitive user, order, and system information in plain language. This is especially risky because such data may include addresses, customer identifiers, order contents, internal IDs, and troubleshooting artifacts that should remain within controlled support channels and only in minimized form.
The document provides end-to-end login, session-cookie reuse, and order-submission instructions without any explicit warning about handling passwords, EGG_SESS cookies, or the irreversible effects of placing and cancelling orders. In an agent skill context, this can lead implementers to collect credentials unsafely, persist session tokens, or trigger real purchases without adequate user confirmation and consent boundaries.
This example shows external transmission of login credentials to a third-party service and normalizes sending plaintext password fields in API requests. Even though HTTPS is used, the skill context is sensitive because an agent may be implemented to collect and forward user credentials, creating credential-handling, logging, and secret-exposure risks.
curl --location --request POST 'https://h5vip.colipu.com/api/vip/login' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
"loginName": "147****6938",
This example transmits an authenticated session cookie (EGG_SESS) to an external endpoint, which teaches implementers to replay bearer-like session material. In an agent setting, leaked or mishandled session cookies could enable unauthorized searches and become a stepping stone to more sensitive order operations.
curl --location --request POST 'https://h5vip.colipu.com/api/b2bSearchApi/SearchByKeyWord' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
This endpoint initiates pre-submission of a real purchase order using authenticated session state, receiver data, cost center, SKU, price, and quantity. In a procurement skill, documenting a direct path to order creation without an explicit confirmation/safety gate materially increases the risk of unauthorized or accidental purchases.
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/create' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
This example confirms order submission and therefore crosses from preparatory actions into committing a transaction. In the skill context, exposing this as a straightforward API call without mandated user re-confirmation or authorization checks creates a strong risk of irreversible or costly external actions triggered by prompt confusion, misuse, or session compromise.
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/orderConfirm' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/getOrderCreateResult' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{ "GuId": "05cb0d9abd7c427bbfa272f13a0e5380" }'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location --request POST 'https://h5vip.colipu.com/api/order/orderlist' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
The module docstring and all user-facing prompts are written exclusively in Chinese, indicating the skill is designed to operate in a single language without opt-in or alternative locale support. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice or documented justification.
The quick_order method performs a full purchase flow—search, receiver/cost center selection, pre-submit, confirmation, and order creation polling—without any interactive user confirmation or policy guardrail. In a procurement assistant, this creates a direct path to unauthorized transactions if the method is exposed through an agent tool or invoked from higher-level automation.
The code explicitly documents an internal/testing-only auto-order capability, but still ships the functionality in the same client used for user-facing procurement actions. Test-only purchase paths are dangerous because they are easily reused, accidentally exposed, or called by an agent despite comments saying they should not be used in normal flows.
The natural-language docstring is entirely in Chinese and presents usage only in that language, which can impose a locale-specific interaction model without user opt-in. There is no indication that the skill is intentionally region-specific or that alternative language use is supported.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
from colipu_client import ColipuClient
def get_product_info(client, item_id):
"""获取商品详情(从 GetAttributeGroupList),失败则返回 None"""
url = f"{client.config.base_url}/api/b2bApi/GetAttributeGroupList"
resp = client.session.get(url, params={"ItemId": item_id}, headers=client._get_headers())
try:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
from colipu_client import ColipuClient
def get_product_info(client, item_id):
"""获取商品详情(从 GetAttributeGroupList),失败则返回 None"""
url = f"{client.config.base_url}/api/b2bApi/GetAttributeGroupList"
resp = client.session.get(url, params={"ItemId": item_id}, headers=client._get_headers())
try:
No suspicious patterns detected.