Back to skill

Security audit

科力普采购助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Colipu procurement helper, but some shipped paths can place business orders without the confirmation the skill promises.

Review before installing. Use only with a Colipu account whose purchasing authority you are willing to expose to this skill, avoid `colipu_order.py`, `colipu_search.place_order()`, and `quick_order()` until they enforce a final per-order confirmation, set strict quantity and budget limits externally, and do not log or share passwords, cookies, full request bodies, full responses, addresses, or order details unless redacted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/colipu_order.py:103
Finding

Financial orders can be submitted without mandatory user confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/colipu_order.py:39
Finding

Unvalidated order quantities can cause excessive or malformed purchases

Content
View full analysis
0: items.append(client.build_order_item( item_sku_id=detail["ItemSkuId"], sale_price=detail["SalePrice"], sale_qty=qty )) subtotal = detail["SalePrice"] * qty total += subtotal else: items.append(client.build_order_item( item_sku_id=item_id, sale_price=0, sale_qty=qty )) ``` ### Technical Analysis Integer conversion only validates the input's data type. It does not enforce the business invariant that an order quantity must be positive and reasonably bounded. Values such as `0`, negative integers, or extremely large integers are accepted and sent to the remote API as `SaleQty`. The server may reject some malformed values, but client-side security must not rely exclusively on undocumented server behavior. Excessively large positive quantities are especially dangerous because they may represent syntactically valid orders. The risk is amplified by the separate confirmation bypass: an extreme quantity can be submitted without a final user review. ### Attack Path 1. An attacker-influenced request, typo, or automation error supplies an argument such as `"1384061,1000000"`. 2. The script converts `1000000` to an integer and accepts it without bounds checking. ...[truncated 1060 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/colipu_client.py:469
Finding

Authentication session material is disclosed in terminal and automation logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/colipu_client.py:88
Finding

Network requests lack bounded connection and read timeouts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full procurement assistant supporting the entire flow: product search, placing orders, viewing order details, querying orders, and canceling orders. The supplied code chunk implements only one part of that scope: placing an order for explicitly provided item IDs and quantities. It logs in, looks up product details, chooses the first receiver and cost center, pre-creates and confirms the order, and prints success/failure information. There is no implementation here for searching products generally, retrieving existing order details, listing/querying orders, or canceling orders. While a single file may represent only part of a larger skill, based on this chunk alone the behavior is materially narrower than the declared end-to-end assistant capability, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

该代码块的实际功能集中在商品搜索与下单,且会使用账号密码登录并调用收货人、成本中心、预下单和确认下单相关接口。这与声明中的“商品搜索、下单”部分一致,但声明强调覆盖“订单详情、订单查询、取消订单全流程”,而本代码块中没有对应实现,因此存在描述大于实际行为的能力不匹配。未发现额外的高风险未声明能力;问题主要是声明的功能范围明显超出此代码块实际提供的能力。

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/buy_products.py (reported line 14)May include surrounding context.

python
from colipu_client import ColipuClient

if os.name == "nt":
    os.system("chcp 65001 >nul 2>&1")

def _err(msg):
    print(f"\n[X] {msg}\n")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script proceeds from pre-submission directly to order confirmation without any interactive confirmation gate, dry-run mode, or explicit user acknowledgment. In a procurement skill, this can cause unauthorized or accidental purchases, especially if invoked by an agent pipeline that passes user intent ambiguously or with manipulated arguments.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function executes confirm_order directly, which is a destructive external action that can create real purchase orders, yet there is no in-function approval check, confirmation prompt, or caller-supplied signed intent. In the context of a B2B purchasing skill, this is especially dangerous because accidental invocation, prompt confusion, or misuse of the tool can commit organizational funds and route goods to default recipients or cost centers.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIG.md (reported line 97)May include surrounding context.

⚠️ client.quick_order(...) 会跳过用户确认环节,仅供自动化测试 / 内部脚本,正式 Agent 流程不要直接使用。

curl 命令调用

bash
# 1. 登录

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents use of environment variables, shell commands, and direct network/API access, but it does not declare any explicit tool scope or allowed-tools boundaries. Without least-privilege restrictions, an agent runtime may grant broader capabilities than necessary, increasing the blast radius if the skill is mis-triggered, misused, or prompt-injected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger language is broad enough to activate on common procurement-related phrasing, including generic mentions of buying or calling the Colipu API. In a skill with purchasing and cancellation capabilities, overbroad triggering increases the chance of unintended invocation and action on ambiguous user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

The skill relies on session-cookie authentication via EGG_SESS and repeatedly instructs the agent to carry that cookie across requests. While session reuse is normal, documenting session persistence without explicit storage, lifetime, redaction, and non-logging controls creates risk of token leakage or misuse if the agent stores, echoes, or forwards the cookie improperly.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
|---|------|------|------|-------------|
| 1 | `/api/vip/login` | POST | 账号密码登录 | 响应头 `Set-Cookie.EGG_SESS`、`Data.customerId` |
| 2 | `/api/b2bSearchApi/SearchByKeyWord` | POST | 关键词搜索商品 | `Data[].ItemId`、`Data[].SalePrice`、`Data[].ItemFullName` |
| 3 | `/api/b2bApi/GetAttributeGroupList` | GET | 商品详情(属性、起订量等) | `Data[].AttributeList`、`Data[].ItemAtte` |
| 4 | `/api/accountApi/receiver/list/0` | GET | 收货地址列表 | `[].ReceiverId`、`[].Status==A` |
| 5 | `/api/crm/getConcenter?IsGroupPower=N` | GET | 成本中心列表 | `Data[].CostCenterId`、`Data[].Status==A` |
| 6 | `/api/confirm/create` | POST | 预提交订单(拿 GuId) | `Data.Success`、`Data.Message`(=GuId) |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown includes an order-cancellation operation but does not define a mandatory explicit user confirmation step analogous to the one required for order placement. Cancellation is a destructive business action, and omission of a hard confirmation control raises the risk of accidental or socially engineered order cancellation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to help compose support emails containing account identifiers plus request/response bodies and reproduction data. Even though it mentions desensitization in one section, the surrounding guidance still encourages disclosure of sensitive operational and transaction data in natural-language communications, which can leak personal, account, or commercial information outside the system boundary.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Telling the agent to include account details and full API request/response content in support emails creates a clear risk of exfiltrating sensitive user, order, and system information in plain language. This is especially risky because such data may include addresses, customer identifiers, order contents, internal IDs, and troubleshooting artifacts that should remain within controlled support channels and only in minimized form.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document provides end-to-end login, session-cookie reuse, and order-submission instructions without any explicit warning about handling passwords, EGG_SESS cookies, or the irreversible effects of placing and cancelling orders. In an agent skill context, this can lead implementers to collect credentials unsafely, persist session tokens, or trigger real purchases without adequate user confirmation and consent boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

This example shows external transmission of login credentials to a third-party service and normalizes sending plaintext password fields in API requests. Even though HTTPS is used, the skill context is sensitive because an agent may be implemented to collect and forward user credentials, creating credential-handling, logging, and secret-exposure risks.

Content

Scanner excerpt · references/api.md (reported line 24)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://h5vip.colipu.com/api/vip/login' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{
  "loginName": "147****6938",

External Transmission

Medium
Category
Data Exfiltration
Confidence
75% confidence
Finding

This example transmits an authenticated session cookie (EGG_SESS) to an external endpoint, which teaches implementers to replay bearer-like session material. In an agent setting, leaked or mishandled session cookies could enable unauthorized searches and become a stepping stone to more sensitive order operations.

Content

Scanner excerpt · references/api.md (reported line 107)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://h5vip.colipu.com/api/b2bSearchApi/SearchByKeyWord' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This endpoint initiates pre-submission of a real purchase order using authenticated session state, receiver data, cost center, SKU, price, and quantity. In a procurement skill, documenting a direct path to order creation without an explicit confirmation/safety gate materially increases the risk of unauthorized or accidental purchases.

Content

Scanner excerpt · references/api.md (reported line 317)May include surrounding context.

请求示例(多 SKU 合并为一单)

bash
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/create' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example confirms order submission and therefore crosses from preparatory actions into committing a transaction. In the skill context, exposing this as a straightforward API call without mandated user re-confirmation or authorization checks creates a strong risk of irreversible or costly external actions triggered by prompt confusion, misuse, or session compromise.

Content

Scanner excerpt · references/api.md (reported line 383)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/orderConfirm' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 423)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://h5vip.colipu.com/api/confirm/getOrderCreateResult' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{ "GuId": "05cb0d9abd7c427bbfa272f13a0e5380" }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 482)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://h5vip.colipu.com/api/order/orderlist' \
--header 'Cookie: EGG_SESS=xxxxxx' \
--header 'content-type: application/json;charset=UTF-8' \
--data-raw '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing prompts are written exclusively in Chinese, indicating the skill is designed to operate in a single language without opt-in or alternative locale support. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick_order method performs a full purchase flow—search, receiver/cost center selection, pre-submit, confirmation, and order creation polling—without any interactive user confirmation or policy guardrail. In a procurement assistant, this creates a direct path to unauthorized transactions if the method is exposed through an agent tool or invoked from higher-level automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code explicitly documents an internal/testing-only auto-order capability, but still ships the functionality in the same client used for user-facing procurement actions. Test-only purchase paths are dangerous because they are easily reused, accidentally exposed, or called by an agent despite comments saying they should not be used in normal flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language docstring is entirely in Chinese and presents usage only in that language, which can impose a locale-specific interaction model without user opt-in. There is no indication that the skill is intentionally region-specific or that alternative language use is supported.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api.md (reported line 152)May include surrounding context.

md
from colipu_client import ColipuClient

def get_product_info(client, item_id):
    """获取商品详情(从 GetAttributeGroupList),失败则返回 None"""
    url = f"{client.config.base_url}/api/b2bApi/GetAttributeGroupList"
    resp = client.session.get(url, params={"ItemId": item_id}, headers=client._get_headers())
    try:

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api.md (reported line 159)May include surrounding context.

md
from colipu_client import ColipuClient

def get_product_info(client, item_id):
    """获取商品详情(从 GetAttributeGroupList),失败则返回 None"""
    url = f"{client.config.base_url}/api/b2bApi/GetAttributeGroupList"
    resp = client.session.get(url, params={"ItemId": item_id}, headers=client._get_headers())
    try:

Static analysis

No suspicious patterns detected.