Back to skill

Security audit

淘宝返利

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Chinese rebate assistant, but it handles withdrawals and persistent account identifiers with under-disclosed privacy and control risks.

Review this skill carefully before installing. It is not obviously malicious, but it can access rebate account state, generate rebate links, and submit withdrawal requests after confirmation. Install only if you trust the rebate service endpoints and publisher, accept that WeChat/OpenID and shopping data may be stored locally and sent to remote services, and can tolerate the verbatim-output behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:18
Finding

Forced Verbatim Output Enables Agent Response Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/m01OperationGuide.js:208
Finding

Persistent WeChat OpenID Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.js:182
Finding

Sensitive Identity and Withdrawal State Stored Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 550)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 599)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 613)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/recognizePreciseProductSearch.js (reported line 786)May include surrounding context.

js
if (modelValue && ruleValue) {
        if (preferSpecific) {
            if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
                return ruleValue;
            }
            if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
                return ruleValue;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/recognizePreciseProductSearch.js (reported line 789)May include surrounding context.

js
if (modelValue && ruleValue) {
        if (preferSpecific) {
            if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
                return ruleValue;
            }
            if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
                return ruleValue;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell, network, and environment-backed capabilities through documented CLI scripts and API-dependent flows, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an avoidable over-privilege condition where the runtime may grant broader access than the narrowly described cashback workflows require, increasing blast radius if downstream scripts are compromised or misrouted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Broad triggers like '返利', '教程', or balance/authorization phrases can cause accidental invocation from ordinary conversation, leading the skill to collect sensitive shopping/account context or initiate financial workflow steps unexpectedly. In a skill that can query balances and prepare withdrawals, overbroad invocation raises the risk of confused-deputy behavior and unintended state transitions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill description and all trigger and response instructions are written exclusively in Chinese, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Routing based on simple keyword or URL presence without clear scope constraints can be abused or accidentally triggered by quoted text, pasted examples, or unrelated discussion. Because the skill routes into networked cashback/search/account flows, weak routing increases the chance of processing untrusted content as if it were an intentional financial or shopping request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This file defines all routing inputs as Chinese-language phrases only, with no indication that users can choose another language or locale. Per the policy, forcing a specific language without documented opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generic JSON save helper performs filesystem writes, and it is used throughout this file to persist machine codes, auth state, OpenID bindings, and pending withdrawal/auth records. In this code file there is no confirmation prompt, user-facing log/print, or comment/docstring disclosing that such local state is being stored.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a rebate assistant with bounded user-facing scenarios, but this code adds a shell-level dependency by spawning curl for both rebate API access and arbitrary URL fetching. Subprocess execution is a stronger capability than ordinary HTTP requests and is not declared or obviously required by the manifest's functional description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill only works in three user scenarios: S01 authorization/tutorial, S02 link rebate, and S03 product search. This file implements a separate pending-withdraw request lifecycle with amount, openid, expiry, and confirmation state persisted locally, which is a substantive capability not reflected in the stated scenario boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code loads model provider configuration from a local file and can send prompts to an arbitrary configured external LLM endpoint, which exceeds the stated rebate-assistant scope. In a skill that processes user messages and local identity/auth context, this creates a clear data exfiltration path to third-party services if configuration is changed or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code reads provider.apiKey from configuration and sends it in an Authorization header to an external model endpoint. There is no user-facing warning, logging, or explanatory comment here indicating that credentials are being used for an outbound API call.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function sends system and user prompt content to a remote model provider, creating an external data transmission channel for user messages and potentially contextual internal data. In this skill, which handles identity-, auth-, and rebate-related workflows, undisclosed prompt export increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends HTTP/HTTPS requests to arbitrary URLs and can include caller-supplied headers and body data, which may transmit user or system data off-host. The file contains no confirmation prompt, logging, print statement, or explanatory comment/docstring disclosing that network transmission occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains extensive user-facing instructional text entirely in Chinese, including onboarding, withdrawal guidance, and command phrasing such as replies the user should send. There is no indication that the skill offers language selection or that the Chinese-only locale is a documented, justified regional constraint, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.