Back to skill

Security audit

唯品会商品详情

Security checks for vulnerabilities and agentic risk

Overview

This Vipshop product-detail skill can query products, but it automatically uses stored account tokens and can print a login-bearing URL that exposes the user's access token.

Review this skill carefully before installing. It should not display exchange-token links or embed account access tokens in URLs, and installing or invoking the login dependency should require explicit user approval with pinned, verified package identity. Avoid sharing any generated product links from the current implementation; if already used, consider refreshing or revoking the Vipshop login session.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/exchange_link_builder.py:165
Finding

Live Vipshop Access Token Exposed in Generated Product URL

Content
View full analysis
, ts={timestamp}") # Convert to JSON string json_str = json.dumps(data_obj, separators=(",", ":")) log(f"JSON string: {json_str[:50]}... (length: {len(json_str)})") # Base64 encode base64_str = base64.b64encode(json_str.encode("utf-8")).decode("utf-8") log(f"Base64 result: {base64_str[:50]}... (length: {len(base64_str)})") # Generate signature signature = _generate_signature(base64_str, secret) log(f"Generated signature: {signature[:20]}... (length: {len(signature)})") # Construct complete link base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) ``` The resulting credential-bearing URL is placed in the command output: ```python # 8. Link: generate linked-login URL containing an exchange token brand_id = base.get("brandId", "") if brand_id and product_id: result["链接"] = build_product_link(brand_id, product_id) ``` The signing secret is also embedded directly in the source at `scripts/exchange_link_builder.py:39-46`: ```python def _get_secret() -> str: """ Get secret key Returns: Secret key string """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ### Technical Analysis The value placed in the `dt` query parameter is a Base64 encoding of a JSON object containing the live `PASSPORT_ACCESS_TOKEN`. Base64 provides no confidentiality: any recipient can URL-decode and Base64-decode the parameter without k ...[truncated 2305 chars]
Remediation
View remediation
str: return ( f"https://detail.vip.com/" f"detail-{brand_id}-{product_id}.html?pcf=AIClaw" ) ``` 2. Do not print, serialize, log, or otherwise return `PASSPORT_ACCESS_TOKEN`. 3. If authenticated link exchange is essential, use a server-generated, narrowly scoped, single-use code that: - Cannot be decoded into the underlying account credential - Expires within a very short period - Is restricted to the intended destination - Cannot be reused for unrelated authenticated operations 4. Remove the hardcoded signing secret. Store secrets in an appropriate secret-management system and rotate the disclosed value. 5. Revoke or rotate access tokens that may already have appeared in generated links or transcripts. 6. Update `SKILL.md` so the Agent never displays URLs containing authentication credentials. 7. Add automated tests that decode every generated query parameter and fail if access tokens, cookies, or other secrets are recoverable. 8. Redact sensitive query parameters from application, proxy, browser, and Agent logs. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:117
Finding

Automatic Installation and Execution of an Unpinned External Login Skill

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating and persisting device identifiers such as mars_cid and storing device.json in the user's home directory extends the skill into persistent tracking and local state management that is not disclosed by the stated product-detail purpose. Hidden identifier generation can create privacy, persistence, and reviewability risks, especially when tied to account-linked commerce actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Generating and persisting device identifiers such as mars_cid and storing device.json in the user's home directory extends the skill into persistent tracking and local state management that is not disclosed by the stated product-detail purpose. Hidden identifier generation can create privacy, persistence, and reviewability risks, especially when tied to account-linked commerce actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Generating and persisting device identifiers such as mars_cid and storing device.json in the user's home directory extends the skill into persistent tracking and local state management that is not disclosed by the stated product-detail purpose. Hidden identifier generation can create privacy, persistence, and reviewability risks, especially when tied to account-linked commerce actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that returned product links may include exchange tokens that support automatic login, but it gives no warning that such URLs are sensitive credentials. Exposing or sharing these links in chat output can leak session-bearing authentication artifacts to logs, transcripts, or unintended recipients.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the AI to display auto-login exchange-token URLs directly to the user. These URLs function like bearer credentials for session transfer, so exposing them in natural-language output risks credential leakage through chat history, logging systems, screenshots, or forwarding.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This module’s stated purpose is to build authenticated exchange-token login URLs, which is materially different from the declared skill purpose of product-detail lookup. In the context of a product-detail skill, introducing login-link generation expands capability into session transfer or account access flows, creating a strong indicator of hidden credential-handling behavior and possible unauthorized authentication bridging.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hard-coded signing secret allows anyone with code access to mint valid signed exchange-token URLs indefinitely until the secret is rotated. In this context, the secret is unrelated to simple product lookup and directly enables forgery of authenticated links, greatly increasing the risk of unauthorized account access or abuse of the exchange mechanism.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill supports querying by 商品ID or 商品链接, but the README repeatedly documents only 商品ID input and the execution flow passes only <product_id> to the script. This is a semantic mismatch between the declared skill capability and the described implemented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs the agent to automatically install and invoke another skill, including blocking login flow, without a clear user-consent boundary. That expands the skill's effective privileges from product lookup to system modification and cross-skill orchestration, which can lead to unexpected code execution paths or abuse if the dependency is malicious, compromised, or replaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented behavior says the system may automatically install and run another skill on the user's machine if login support is missing, but this is not surfaced as a clear warning. Silent dependency installation and execution is dangerous because it changes the local environment and introduces a new trust boundary without informed approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly relies on reading stored login state from ~/.vipshop-user-login/tokens.json and transmitting cookie/token-derived authentication material to Vipshop APIs, yet the documentation does not prominently warn users about this sensitive data handling. Hidden or under-disclosed credential use reduces informed consent and increases the risk of users unknowingly authorizing access with persistent account tokens.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope while its documented behavior includes reading local token files, writing device identifiers, and making network requests. Without a least-privilege tool declaration, an agent may execute broader capabilities than users or reviewers expect, increasing the chance of unauthorized file access or network use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill triggers whenever a user wants to view product details and includes a broad non-exhaustive list such as '看商品详情' and '查活动优惠', followed by '包括但不限于'. This makes invocation scope ambiguous and does not provide exclusion conditions or clear limits, increasing the chance of unintended activation in ordinary shopping-related conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The overview repeats that the skill should trigger whenever the user wants product details, again using broad examples and '包括但不限于' without specifying when the skill should not activate. Because this is natural-language activation guidance in markdown, it creates unclear trigger boundaries for the agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to automatically install another skill via clawhub, which is a system-modifying action outside the narrow expectation of a product-detail lookup. Auto-installing dependencies at runtime expands trust boundaries and can introduce unreviewed code execution paths without explicit user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown directs the agent to install software and initiate account login flows automatically, yet it does not prominently warn that these are system-modifying and account-access actions. Missing consent and warning language is dangerous because users may be led into privileged operations under the guise of a simple product query.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Directing the agent to run a separate login script in blocking mode turns a shopping-detail skill into an account-access orchestrator. This is risky because it can trigger sensitive authentication flows and external code execution without a clear consent checkpoint proportional to the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script loads login tokens from a local file, extracts authentication cookies, and sends them in HTTP requests to external vip.com endpoints. Although this is part of the data-fetching logic, there is no confirmation prompt, print statement, or user-facing disclosure in the code warning that stored account session data will be used and transmitted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads PASSPORT_ACCESS_TOKEN from another skill’s local credential store and uses it to construct an authenticated exchange link. Cross-skill credential reuse violates isolation boundaries and can enable account/session takeover or impersonation if the generated link is consumed by an attacker or unintended component.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill silently accesses a local login token and derives an authenticated link without any user-facing disclosure or consent. Even if intended for convenience, undisclosed handling of authentication material is dangerous because it obscures sensitive data use and can enable covert session manipulation in a skill whose declared function is only to view product details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The test harness prints generated exchange links that contain token-derived authentication data, which can leak via terminal logs, CI output, shell history capture, or support tooling. Because the link is derived from a live access token and signature, exposing it can permit replay or unauthorized use during its validity window.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code persists a device identifier under the user's home directory even though this skill is described as a product-detail query helper. Persisting a stable device ID creates cross-session tracking state and local artifact retention, which is privacy-sensitive and expands the skill's capabilities beyond the minimally necessary scope; if other local processes or users can read the file, the identifier may also be reused to impersonate or correlate the user's device context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The line states the implementation uses only Python standard library, which suggests a self-contained script. Elsewhere, the README requires installing and invoking vipshop-user-login via clawhub install and blocking skill execution, so the documentation presents a misleadingly narrower implementation story than what the skill actually directs the agent to do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Accept-Language header is fixed to prefer zh-CN and zh, which imposes a locale preference regardless of user settings or input. This is a natural-language policy concern because the skill does not provide any opt-in, fallback, or configuration for language selection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The create() and encrypt() docstrings repeatedly claim the output is '安全加密' (securely encrypted), but the implementation merely combines a timestamp with random hex and replaces one character based on a sum modulo calculation. This is an active contradiction between documentation and actual behavior, which could mislead maintainers about the security properties of the identifier.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.