Back to skill

Security audit

jd-new-arrivals

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only JD product search helper that uses a disclosed cloud proxy, with no evidence of persistence, destructive behavior, or hidden data collection.

Install this only if you are comfortable with shopping queries being sent to the configured Tencent SCF proxy. Keep PROXY_URL pointed at the intended trusted service and treat PROXY_TOKEN as a scoped service credential. The skill appears limited to returning product information and purchase links, not making purchases or changing account data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tainted flow: 'req' from os.environ.get (line 27, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The script sends an authentication secret from the environment (PROXY_TOKEN) to a network endpoint whose URL is also fully controlled by an environment variable. If PROXY_URL is misconfigured or attacker-controlled, the token and all user query data will be exfiltrated to an arbitrary server. In a skill context, this is materially risky because the tool is explicitly designed to relay user search parameters through a proxy service.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
headers = {"Content-Type": "application/json", "X-Proxy-Token": PROXY_TOKEN}
    req = urllib.request.Request(PROXY_URL, data=payload, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.URLError as e:
        if "timed out" in str(e).lower():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares network and environment-variable-backed behavior (PROXY_URL, PROXY_TOKEN, cloud proxy access) without an explicit permission or allowed-tools scope. This weakens least-privilege controls and makes it harder for the hosting platform or reviewers to verify what external access the skill is supposed to have, increasing the risk of unauthorized data egress or unexpected outbound requests if the implementation changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The quick-start examples present invocation phrases like "京东最近有什么新品" and "优惠力度最大的新品" as natural-language triggers without clarifying boundaries or exclusion conditions. These are broad everyday shopping requests that could match user intent outside this specific skill, increasing the risk of unintended activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool transmits user-supplied search parameters together with a proxy authentication token to an external SCF service, but the code provides no disclosure that user queries leave the local agent boundary. This creates a privacy and trust issue, especially because search terms may contain sensitive consumer interests or other personal data entered by users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script reads PROXY_TOKEN from the environment and uses it for outbound authentication, which is access to a sensitive credential. There is no user-facing notice in this file explaining that the skill depends on and uses an environment-provided secret for remote requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.