Back to skill

Security audit

咸鱼自动发货

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Xianyu auto-fulfillment tool, but it can automatically act on a live seller account and expose product keys through weak validation, logs, and optional third-party notifications.

Install only after reviewing and hardening the automation. Use a dedicated browser profile/account, require manual confirmation or authoritative order verification before sending keys, avoid logging or storing full keys in plaintext, pin and verify dependencies, and remove notification/API examples that send buyer identifiers or keys unless you have a trusted, privacy-reviewed destination.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
xianyu-monitor-final.sh:112
Finding

Buyer-Controlled Chat Text Can Trigger Unauthorized Key Delivery

Content
View full analysis
&1) # 检查是否为付款消息 if echo "$snapshot" | grep -q "我已付款\|等待你发货\|去发货"; then log "💰 检测到付款消息!" return 0 fi return 1 } ``` ### Technical Analysis The regular expression uses alternatives, so the condition succeeds if the page snapshot contains any one of the following phrases: - “I have paid” - “Waiting for you to ship” - “Ship now” It does not establish that the matching text belongs to an authentic Xianyu system payment card. It also does not require the payment message and fulfillment button to appear together or verify the order through an authoritative order record. Because ordinary buyer messages are included in the browser snapshot, a buyer can provide one of the accepted phrases as chat content. The script may then classify that buyer-controlled message as proof of payment. This contradicts the stricter documented design, which states that payment text and the fulfillment button should both be present and that ordinary user-written text should be excluded. ### Attack Path 1. An attacker opens a chat with the seller. 2. The attacker sends a message containing one accepted phrase, such as the equivalent of “I have paid.” 3. The monitor detects the recent conversation and enters it. 4. `analyze_chat` captures a snapshot containing the attacker’s message. 5. The alternation-based `grep` condition returns success. 6. The main loop calls `send_key`. 7. A key is removed from the seller’s pool and typed into the chat despite the absence of a verified payment. ### Impact Assessment A remote Xianyu user may obtain digital goods without making a valid payment. The attacker does not gain operating-system privileges, but can cause unauthorized business actions ...[truncated 315 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
xianyu-monitor-final.sh:139
Finding

Predictable Shared Temporary Files Permit Snapshot Disclosure and Symlink Attacks

Content
View full analysis
&1 > /tmp/snapshot_input.txt # 尝试发送消息 local msg="您的秘钥:$key,祝您使用愉快!" log "💬 发送消息:$msg" agent-browser type "$msg" > /dev/null 2>&1 sleep 1 # 查找并发送按钮 agent-browser snapshot -i 2>&1 > /tmp/snapshot_send.txt local send_btn=$(grep -i "发送\|send" /tmp/snapshot_send.txt | head -1) ``` ### Technical Analysis The script writes browser snapshots to fixed, globally predictable paths under `/tmp`. It does not: - Create the files atomically - Enforce restrictive permissions - Verify file ownership or type - Protect against symbolic links - Remove the files after use On a multi-user system, `/tmp` is normally writable by all local users. Another local account can pre-create either path as a symbolic link to a file writable by the monitor’s user. Shell redirection then follows that link and truncates or overwrites the target. The snapshots may also contain chat text, buyer information, order details, interface references, and other authenticated-session content. Depending on the process umask and existing file permissions, this information may remain readable after the script exits. ### Attack Path 1. A local attacker predicts the fixed path `/tmp/snapshot_send.txt`. 2. The attacker creates a symbolic link from that path to a file writable by the victim account, or creates a permissive regular file. 3. The victim runs the monitor. 4. Shell redirection follows the attacker-controlled path. 5. Browser snapshot content overwrites the linked target or is stored in an attacker-readable file. 6. The attacker reads exposed chat/order data or benefits from corruption of the selected target. ### Impact Assessment Exploitation requires local access but does not require access to the authenticated browser profile itself. Potential effect ...[truncated 391 chars]
Remediation
View remediation
"$snapshot_send" 2>&1 send_btn=$(grep -i "发送\|send" "$snapshot_send" | head -1) ``` An in-memory alternative is preferable: ```bash local interactive_snapshot interactive_snapshot=$(agent-browser snapshot -i 2>&1) || return 1 local send_btn send_btn=$(printf '%s\n' "$interactive_snapshot" | grep -i "发送\|send" | head -1) ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
fulfillment-templates/02-key-pool.sh:48
Finding

Fulfillment Keys Are Persisted and Logged in Plaintext

Content
View full analysis
> "$USED_KEYS_FILE" echo "$key" ``` ```bash fulfill_order() { echo "📦 从秘钥池获取秘钥..." # 初始化秘钥池 init_key_pool # 获取秘钥 key=$(get_key_from_pool) if [ $? -ne 0 ]; then echo "❌ 获取秘钥失败" return 1 fi echo "✅ 获取到秘钥:$key" # 发送秘钥 agent-browser type "您的秘钥:$key,祝您使用愉快!" ``` The standalone monitor also logs the complete outgoing message: ```bash log "✅ 获取到秘钥:$key" local msg="您的秘钥:$key,祝您使用愉快!" log "💬 发送消息:$msg" ``` ### Technical Analysis The implementation writes complete fulfillment keys to `used-keys.txt` and operational logs. It does not establish restrictive file permissions before creating those files. Product keys are bearer-style secrets: possession is generally sufficient for redemption or access. Keeping complete values in routine logs unnecessarily expands the number of files and systems containing sensitive material. Logs may be included in backups, troubleshooting archives, synchronization services, or source-control commits. The used-key record may be operationally necessary, but retaining the complete key is not. A one-way identifier, encrypted record, or redacted suffix is sufficient for most auditing requirements. ### Attack Path 1. The monitor allocates a product key. 2. The complete key is appended to the used-key record. 3. The same key is printed to standard output and may be copied into the daily fulfillment log. 4. A local user, backup operator, support recipient, synchronization service, or accidental repository commit obtains the log file. 5. The exposed key is ...[truncated 562 chars]
Remediation
View remediation
> "$USED_KEYS_FILE" echo "Allocated fulfillment key ending in $key_suffix" ``` If customer support requires recovery of the original value, use authenticated encryption with keys stored outside the project directory rather than plaintext logs. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
fulfillment-templates/02-key-pool.sh:31
Finding

Non-Atomic Key Allocation Can Duplicate or Corrupt Fulfillment Inventory

Content
View full analysis
/dev/null else # Linux sed -i "/^$key$/d" "$KEY_POOL_FILE" 2>/dev/null fi # 记录到已使用秘钥 echo "[$(date '+%Y-%m-%d %H:%M:%S')] $key" >> "$USED_KEYS_FILE" ``` ### Technical Analysis Key selection, deletion, and history recording are independent filesystem operations with no lock or transaction. Two monitor instances can read the same first key before either process removes it. Both instances may then send that key to different buyers. The code also suppresses deletion errors and proceeds to record and return the key, so a failed update does not prevent fulfillment. Additionally, `$key` is inserted directly into a `sed` regular expression. A key containing regex metacharacters, backslashes, or the `/` delimiter can alter the match, cause a syntax failure, or remove unintended lines. Although the key pool is normally seller-controlled, imported or generated inventories can contain such characters. ### Attack Path #### Concurrent allocation 1. Two monitor instances process orders at approximately the same time. 2. Both execute the `grep | head -1` pipeline before either deletion completes. 3. Both receive the same key. 4. Each independently invokes `sed`. 5. Both workflows return the same key and send it to separate buyers. #### Inventory parsing failure 1. A key contains a character meaningful to `sed`, such as `/`, `.`, `*`, `[`, or `\`. 2. The ke ...[truncated 832 chars]
Remediation
View remediation
"${KEY_POOL_FILE}.lock" flock -x 9 || return 1 key=$(awk '!/^#/ && NF { print; exit }' "$KEY_POOL_FILE") || return 1 [ -n "$key" ] || return 1 tmp_file=$(mktemp "${KEY_POOL_FILE}.XXXXXX") || return 1 awk -v target="$key" ' !removed && $0 == target { removed=1; next } { print } END { if (!removed) exit 1 } ' "$KEY_POOL_FILE" > "$tmp_file" || { rm -f "$tmp_file" return 1 } mv -- "$tmp_file" "$KEY_POOL_FILE" || return 1 printf '[%s] %s\n' "$(date '+%Y-%m-%d %H:%M:%S')" "$key_id" \ >> "$USED_KEYS_FILE" || return 1 ``` For portability and reliable transactions, migrate the pool to SQLite and allocate keys using a single exclusive transaction. ]]>

T08 · Insecure Dependencies

Warning
Location
quick-start.sh:11
Finding

Unpinned Global Dependency Is Granted Access to an Authenticated Browser Profile

Content
View full analysis
/dev/null; then echo "❌ agent-browser 未安装" echo "正在安装..." npm install -g agent-browser agent-browser install echo "✅ agent-browser 安装完成" fi ``` The installed executable is subsequently invoked with the normal Chrome profile: ```bash agent-browser --headed --profile "$PROFILE" open "$CHAT_URL" ``` ### Technical Analysis The quick-start process installs the latest package named `agent-browser` globally from the configured npm registry. It does not pin an exact version, verify an integrity digest, use a lockfile, or validate the package publisher and provenance. Global npm package installation executes package lifecycle scripts with the user’s privileges and places executable commands in a shared command path. The resulting browser automation package is then given access to an authenticated Chrome profile containing the user’s Xianyu session and potentially other browser state. This does not prove that the current dependency is malicious. The vulnerability is the absence of controls limiting the effect of a compromised package release, registry compromise, account takeover, or unexpected future update. ### Attack Path 1. An attacker compromises the dependency publisher, registry path, or a future package release. 2. A user runs `quick-start.sh` when `agent-browser` is absent. 3. `npm install -g agent-browser` downloads and executes the attacker-controlled package or lifecycle script. 4. The package executes with the installing user’s privileges. 5. The installed command is later invoked with the user’s authenticated Chrome profile. 6. The compromised dependency c ...[truncated 692 chars]
Remediation
View remediation
npm ci --ignore-scripts ``` If installation scripts are required, audit them before enabling them. Invoke the project-local executable through `npx --no-install` or an explicit path, and do not grant it access to the user’s general-purpose Chrome profile. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (57)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

�的API

  • 集成第三方发货服务
  • 调用自己的服务器

使用方法:

bash
#!/bin/bash
# fulfillment-templates/05-api-delivery.sh

# 配置
API_ENDPOINT="https://your-api.com/generate-key"
API_KEY="YOUR_API_KEY"

# 调用API生成秘钥
call_api_generate_key() {
    local buyer_nickname="$1"
    local product_title="$2"

    echo "📡 调用API生成秘钥..."

    response=$(curl -s -X POST "$API_ENDPOINT" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{
            \"buyer\": \"$buyer_nickname\",
            \"product\": \"$product_title\",
            \"timestamp\": \"$(date -u +%Y-%m-%dT%H:%M:%SZ)\"
        }")

    # 解析响应(假设返回 {"key": "xxx", "success": true})
    if command -v jq &> /dev/null; then
        key=$(echo "$response" | jq -r '.key')
        success=$(echo "$response" | jq -r '.success')
    else
        # 如果没有jq,使用grep
        key=$(echo "$response" | grep

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an automation framework for Xianyu order/payment monitoring and customizable automatic delivery. The supplied code chunk is instead a utility shell script whose sole function is to display ways to stop a monitoring sub-agent or kill a related process. This is a materially different primary purpose from the declared framework capabilities. While such a script could be ancillary tooling in the same project, this specific chunk does not match the declared behavior and lacks the described payment detection, delivery extensibility, configuration logic, templates, or agent-browser automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an auto-fulfillment framework whose core function is automatic buyer payment detection and customizable delivery of virtual goods. The supplied code does not implement that core behavior. Instead, it is a monitoring loop for the Xianyu chat page: it opens the IM page, takes snapshots, searches for recent-message indicators like '刚刚/分钟前/小时前', and logs possible new conversations. The script explicitly states that automatic entry into chats and processing are not yet implemented and only records logs for manual confirmation. While there are helper functions for pulling keys from a local key pool, those functions are not used by the main loop and no fulfillment occurs. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code transmits the value of SECRET_KEY by typing and sending it through agent-browser, which is a safety-sensitive disclosure of credential-like data. There is no confirmation prompt, no explicit warning to the user at the point of transmission, and no indication in this file that the disclosure is explained before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script logs the actual secret key value to stdout and to a persistent fulfillment log. This creates a direct secret disclosure path: anyone with terminal access, log access, backups, or monitoring visibility can recover unused or recently delivered keys and reuse or steal them.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script writes full secret keys into used-keys.txt, creating a persistent plaintext record of sensitive fulfillment material. Anyone with local access, backups, log collectors, or malware on the host could recover delivered keys and reuse or resell them, defeating the secrecy of the product.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script logs the full delivered key to both stdout and the logfile via log "✅ 获取到秘钥:$key" and later log "✅ 秘钥已发送:$key". This exposes secrets to terminal history, process supervisors, CI logs, remote shells, and local log files, significantly increasing the chance of credential disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly instructs an agent to automatically detect payment and send fulfillment keys in chat, but it does not warn about the irreversible nature of digital goods delivery or the risk of disclosing sensitive keys to the wrong conversation or on false-positive payment detection. In this skill’s context, automatic fulfillment of virtual goods increases the chance of accidental secret exposure and unrecoverable inventory loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow states that the system loads a fulfillment template, retrieves a key from a local key pool, and sends it to chat, yet it omits security guidance on handling the key pool as sensitive data. Because these are transferable digital goods, exposure through logs, misdelivery, local file leakage, or incorrect chat targeting can directly cause financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to launch automation against their real Chrome profile and logged-in Xianyu account, but it does not prominently warn that the tool will act with the full privileges of that live session. That creates meaningful risk of unintended account actions, data exposure, or account takeover consequences if the automation or surrounding scripts malfunction or are modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly shows logs containing buyer nicknames, product names, and even a full delivered key value. In a system that automates fulfillment of virtual goods, documenting and encouraging this logging pattern increases the chance that secrets and customer data are written to plaintext files, which can later be exposed through local compromise, backups, support sharing, or accidental publication.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill embeds substantial shell code and operational automation examples but does not declare any tool scope or allowed-tools restrictions. In an agent ecosystem, this increases the risk that the skill is granted broader execution capability than users expect, especially because the documentation encourages sourcing scripts, running loops, and invoking external commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill discusses automated external notifications and customizable delivery involving third-party services but does not prominently warn about the privacy consequences of transmitting order details and potentially secrets off-platform. In this context, omission of privacy guidance can lead operators to leak buyer data and credentials unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

This snippet transmits order-related data to an external API endpoint using curl. External transmission is not inherently malicious in an API fulfillment template, but it becomes sensitive here because buyer and product data are sent off-platform and the endpoint is arbitrary/user-configured.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

md
echo "📡 调用API生成秘钥..."

    response=$(curl -s -X POST "$API_ENDPOINT" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation expands from browser automation into OS-level automation and arbitrary script execution pathways, including system dialog interaction helpers. That broadens the attack surface because downstream users may copy these snippets into privileged local workflows, enabling unintended local actions beyond the stated browser-only fulfillment purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The notification examples send buyer identifiers and generated keys to third-party services such as Telegram and WeCom, which is unnecessary for core fulfillment and creates a data exfiltration path. Because the transmitted content includes fulfillment secrets and customer information, compromise of those channels or misconfiguration would expose sensitive transactional data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions explicitly forward buyer identity and generated keys to external notification channels in plain operational guidance. That is dangerous because keys are the delivered secret product, and broadcasting them outside the fulfillment context creates a straightforward confidentiality breach.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The explicit Telegram API endpoint highlights outbound transmission to a third-party communications platform. In context, the dangerous aspect is not the domain itself but that the surrounding example uses it to ship transactional secrets and buyer data off-platform.

Content

Scanner excerpt · SKILL.md (reported line 796)May include surrounding context.

md
# 在发货钩子中添加
send_telegram_notification() {
    local message="闲鱼订单已完成\n\n买家:$BUYER_NICKNAME\n秘钥:$key"
    curl -s -X POST "https://api.telegram.org/botYOUR_BOT_TOKEN/sendMessage" \
        -d "chat_id=YOUR_CHAT_ID" \
        -d "text=$message"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The explicit Telegram API endpoint highlights outbound transmission to a third-party communications platform. In context, the dangerous aspect is not the domain itself but that the surrounding example uses it to ship transactional secrets and buyer data off-platform.

Content

Scanner excerpt · SKILL.md (reported line 796)May include surrounding context.

md
# 在发货钩子中添加
send_telegram_notification() {
    local message="闲鱼订单已完成\n\n买家:$BUYER_NICKNAME\n秘钥:$key"
    curl -s -X POST "https://api.telegram.org/botYOUR_BOT_TOKEN/sendMessage" \
        -d "chat_id=YOUR_CHAT_ID" \
        -d "text=$message"
}

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The logging example recommends storing buyer details together with secret keys in logs, concentrating sensitive data in a durable plaintext artifact. Logs are commonly copied, backed up, or exposed to support tooling, so this creates a high likelihood of accidental secret leakage and customer privacy exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template embeds a secret in a shell variable and then automatically transmits it to a buyer via browser automation. Even though this appears intentional for a fulfillment workflow, hardcoding secrets in a distributable template increases the chance of accidental disclosure through source control, logs, screenshots, or reuse across orders, and there is no validation that the recipient is authorized beyond whatever the surrounding automation does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script appends issued keys to a local used-keys log and later prints the retrieved key to stdout, but there is no comment, prompt, or user-facing warning that sensitive credential material will be stored and displayed. Because this file handles secrets, the lack of disclosure increases the risk of accidental exposure through logs, terminal history, or local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script automatically types and sends the secret key through agent-browser, which is a safety-relevant action that transmits sensitive data. Although the action is visible in code, there is no confirmation step or explicit warning that the key will be sent to the active chat or UI target, creating risk of misdelivery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments and user-facing output strings throughout the script are written only in Chinese, including the message sent to the end user. This imposes a language choice without opt-in and no documented justification indicates that the skill is intentionally restricted to a Chinese-language context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The script performs an outbound HTTP POST with order-related data and an authorization bearer token to a configurable external endpoint. In an automation skill that processes customer orders, this increases risk because a misconfigured, compromised, or untrusted endpoint could collect sensitive operational data or abuse the API credential.

Content

Scanner excerpt · fulfillment-templates/05-api-delivery.sh (reported line 30)May include surrounding context.

sh
)

    # 发送请求
    local response=$(curl -s -X POST "$API_ENDPOINT" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "$request_body")

Static analysis

No suspicious patterns detected.