Back to skill

Security audit

Xianyu Sam Order

Security checks for vulnerabilities and agentic risk

Overview

The skill is small and not malicious, but it asks users to store a sensitive marketplace cookie and phone number in a shared local environment file without a real implemented need or adequate safeguards.

Review before installing. Do not put a real Taobao/Xianyu session cookie in the workspace .env for this version; the helper does not need it to perform its current functions. If you use the skill, prefer manual ordering and only provide account details when a specific, implemented action requires them, with secure secret storage and revocation guidance.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:31
Finding

Shared Plaintext Storage of an Unnecessary Authentication Cookie

Content
View full analysis
" # Sam's Club membership account SAM_PHONE="" ``` ### Technical Analysis Authentication cookies are bearer credentials: any party that obtains a valid cookie may be able to impersonate the authenticated user without knowing the account password. Storing such a credential as plaintext in `~/.openclaw/workspace/.env` creates unnecessary exposure to other local processes, Skills, workspace readers, backups, diagnostic tools, or accidental source-control inclusion. The implemented script does not use the cookie to authenticate, query prices, track orders, or place orders. It only reads the named environment variables and reports whether they are present: ```python cookie = os.environ.get("XIANYU_COOKIE", "") sam_phone = os.environ.get("SAM_PHONE", "") ``` Consequently, requesting and retaining `XIANYU_COOKIE` exceeds the minimum privileges required by the current manual-ordering and configuration-check functionality. Although the script does not print the secret value or directly read the `.env` file, the documentation encourages users to create the sensitive plaintext storage condition. ### Attack Path 1. A user follows `SKILL.md` and places a valid Xianyu session cookie in `~/.openclaw/workspace/.env`. 2. The file is left accessible to another local user, process, Skill, backup service, diagnostic utility, or workspace synchronization mechanism. 3. That party reads or otherwise captures `XIANYU_COOK ...[truncated 924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to place a Taobao/Xianyu cookie and phone number into a local .env file without any safety guidance, minimization, or storage protections. Cookies are high-value authentication artifacts; if the workspace, logs, backups, or other skills can access that file, an attacker could hijack the user's marketplace account or abuse their membership and ordering capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language policy requires avoiding forced language or locale constraints unless users are given a choice or the restriction is clearly justified. This skill's metadata, triggers, and instructions are entirely in Chinese, and the file does not state that the skill is China-region-specific or offer any language opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing docstrings and printed help text entirely in Chinese, including setup and ordering instructions. Because the skill does not offer a language or locale choice or document that it is intentionally region-specific, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.