T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Skill instructions override user intent, force authentication, and prevent security remediation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Vipshop shopping skill has a coherent purpose, but it handles login tokens in ways that can expose an account session and it pushes automatic login and installation flows too aggressively.
Install only after reviewing the credential behavior. The main fix needed is to stop putting PASSPORT_ACCESS_TOKEN into displayed URLs, require explicit consent before login, image upload, and installing dependencies, and pin dependencies to reviewed versions.
SKILL.md:3Skill instructions override user intent, force authentication, and prevent security remediation
vipshop-product-detail/scripts/exchange_link_builder.py:39Reusable Vipshop access tokens are reversibly embedded in user-visible URLs
vipshop-user-login/requirements.txt:1Automatic installation uses mutable Skills and unpinned Python dependencies
The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.
The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.
The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.
The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.
The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.
Referenced artifact was not completely inspected
2. 创建 `SKILL.md` 文件,包含完整的技能说明
Referenced artifact was not completely inspected
2. 创建 `SKILL.md` 文件,包含完整的技能说明
The README explicitly requires extracting credential-bearing values such as mars_cid and PASSPORT_ACCESS_TOKEN from stored login state and using them in requests. This is a strong secret-handling anti-pattern: it places raw authentication material into an agent workflow where it may be logged, surfaced in prompts, mishandled, or exfiltrated by prompt injection or downstream tooling.
The trigger description is extremely broad, covering generic shopping and product-discovery language across many platforms. This creates a real risk of accidental activation in unrelated conversations, causing the agent to pivot into this skill and potentially initiate login or commerce-related actions the user did not explicitly request.
The body repeats an overbroad activation scope without clear boundaries or disambiguation criteria, increasing the chance that the skill is invoked for ordinary e-commerce discussion rather than a deliberate request to use Vipshop. In this skill, that ambiguity is more dangerous because activation can cascade into automatic login handling and command execution.
The trigger description is overly broad and includes common shopping-intent phrases, plus it claims coverage for competing platforms' promotion queries. In context, over-triggering is especially dangerous because the skill then attempts login checks, possible auto-installation, and external actions, causing a simple conversational mention to escalate into privileged behavior.
The overview repeats broad trigger conditions without clear boundaries, increasing the chance that unrelated shopping queries invoke this skill. Because the skill's workflow includes checking local token files and potentially initiating login-related actions, broad matching materially raises the risk of unintended credential-adjacent operations.
The skill directs the agent to execute a script from a sibling skill directory (../vipshop-user-login/scripts/vip_login.py --blocking). Cross-skill script execution bypasses normal isolation boundaries, enables unexpected code execution outside the declared skill scope, and could be abused if the neighboring skill contents are modified or untrusted.
The skill advertises and orchestrates capabilities that imply file access, network access, shell/script execution, and credential handling, but it does not declare any explicit tool scope or permissions boundaries. In a skill ecosystem, missing scope declarations increase the chance of over-broad tool access and make it harder for reviewers and users to understand what sensitive operations the skill may perform.
The activation text is broad enough to capture generic shopping or cross-platform comparison requests, not just clear Vipshop-specific intents. Because this skill also involves login-state sharing and credential-related operations, over-broad triggering increases the chance it is invoked in contexts where the user did not intend account-linked actions on Vipshop.
The image-search flow instructs users to provide a local image path and implies upload for remote product search, but it lacks an explicit privacy warning about transmitting local user images off-device. User images may contain faces, location hints, documents, or other sensitive content, so silent upload materially increases privacy risk.
The skill documents automatic login and shared persistent login-state storage at ~/.vipshop-user-login/tokens.json, but it does not clearly warn users about persistence, reuse across subskills, or the privacy/account implications. Persistent token storage combined with automatic reuse can expose account sessions to unintended access, especially on shared systems or when multiple subskills can read the same state.
Telling users to 'directly tell the AI your shopping needs' encourages vague invocation and can trigger the skill for broad shopping intents without platform-specific consent. In this context, that matters because the skill may automatically engage login-state handling or remote requests using the user's account context.
The skill metadata and trigger language are broad enough to match common phrases such as image search or finding similar products, increasing the chance of unintended invocation. Because this skill can access local files, inspect login state, and upload images to remote endpoints, accidental activation has privacy and account-action implications beyond a harmless misfire.
The skill describes local image upload and remote search but does not clearly warn users that their local images will be transmitted to Vipshop network endpoints for analysis. This creates a meaningful privacy risk because users may provide personal, sensitive, or copyrighted images without informed consent regarding off-device transfer.
Standalone trigger examples like '找同款' and '图片搜索' are ambiguous and could match many unrelated user intents. In this skill's context, a false activation may lead the agent to request or use a local image, access stored login state, and send data to Vipshop services without sufficiently specific user intent.
The workflow directs the agent to automatically inspect stored tokens and trigger login actions without a clear user warning or consent checkpoint. Accessing authentication artifacts and initiating account-auth flows are sensitive actions, and doing so implicitly can surprise users and expand the impact of accidental invocation.
The instruction to fully display all script-returned data creates a direct risk of exposing sensitive fields returned by backend APIs, including account-linked data, internal identifiers, tokens, URLs with embedded auth material, or other nonessential metadata. In a shopping/login-integrated skill, indiscriminate disclosure of raw backend payloads materially increases the chance of credential leakage or privacy breaches.
Including an 原始数据 field in the normalized output model encourages downstream agents to preserve and potentially display complete backend responses. That pattern amplifies data-exposure risk because raw payloads often contain fields not meant for end users, including sensitive account, tracking, or authorization-related values.
The example shows running the image-search script before ensuring authentication, which contradicts the earlier requirement to verify login state first. In practice, contradictory operational instructions can cause agents to skip prerequisite checks, leading to unintended account actions, inconsistent behavior, and unsafe automation around authentication state.
No suspicious patterns detected.