Back to skill

Security audit

唯品会技能集

Security checks for vulnerabilities and agentic risk

Overview

This Vipshop shopping skill has a coherent purpose, but it handles login tokens in ways that can expose an account session and it pushes automatic login and installation flows too aggressively.

Install only after reviewing the credential behavior. The main fix needed is to stop putting PASSPORT_ACCESS_TOKEN into displayed URLs, require explicit consent before login, image upload, and installing dependencies, and pin dependencies to reviewed versions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Skill instructions override user intent, force authentication, and prevent security remediation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
vipshop-product-detail/scripts/exchange_link_builder.py:39
Finding

Reusable Vipshop access tokens are reversibly embedded in user-visible URLs

Content
View full analysis
str: """ Get the secret key. Returns: Secret key string. """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` The token is read from the shared credential file: ```python token_file = Path.home() / ".vipshop-user-login" / "tokens.json" with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) cookies = data.get('cookies', {}) token = cookies.get("PASSPORT_ACCESS_TOKEN", "") ``` The complete credential-bearing URL construction is: ```python # Get token token = _get_token() if not token: return target_url # Get secret key secret = _get_secret() # Construct data object timestamp = int(time.time() * 1000) data_obj = {"t": token, "ts": timestamp} # Convert to JSON json_str = json.dumps(data_obj, separators=(",", ":")) # Base64 encode base64_str = base64.b64encode(json_str.encode("utf-8")).decode("utf-8") # Generate signature signature = _generate_signature(base64_str, secret) # Construct complete link base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) return full_url ``` Product search places the resulting URL directly in structured output: ```python # Use build_pr ...[truncated 3914 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
vipshop-user-login/requirements.txt:1
Finding

Automatic installation uses mutable Skills and unpinned Python dependencies

Content
View full analysis
=2.28.0 qrcode>=7.0 Pillow>=9.0.0 packaging>=21.0 ``` ### Technical Analysis The Python requirements specify only minimum versions. They do not provide: - Exact reviewed versions. - Cryptographic hashes. - A lock file. - A trusted package index. - Signature or provenance verification. - Upper bounds protecting against incompatible future releases. As a result, installations performed at different times may retrieve different code from the package registry. The Skill documentation also instructs the agent to install `vipshop-user-login` automatically if it is absent, without requiring explicit user approval or specifying a reviewed immutable version. No malicious third-party package was identified in the supplied project, and the listed package names are not evident typosquatting names. The confirmed weakness is the unsafe and mutable dependency acquisition process, especially when combined with mandatory automatic installation instructions. ### Attack Path 1. A user invokes product search, product detail, or promotion search without the login Skill installed. 2. The Skill instructs the agent to run `clawhub install vipshop-user-login`. 3. Alternatively, missing Python dependencies are installed with `pip` from mutable version ranges. 4. A compromised registry ...[truncated 1023 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (100)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill is framed as a shopping assistant, yet it reportedly reads local credential files, extracts access tokens, uses a hardcoded signing key, and constructs a passport.vip.com exchangeTokenFromApp login/token-exchange link. That is sensitive authentication behavior that can enable account takeover, session abuse, or unauthorized impersonation if the data or link generation is misused.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly requires extracting credential-bearing values such as mars_cid and PASSPORT_ACCESS_TOKEN from stored login state and using them in requests. This is a strong secret-handling anti-pattern: it places raw authentication material into an agent workflow where it may be logged, surfaced in prompts, mishandled, or exfiltrated by prompt injection or downstream tooling.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger description is extremely broad, covering generic shopping and product-discovery language across many platforms. This creates a real risk of accidental activation in unrelated conversations, causing the agent to pivot into this skill and potentially initiate login or commerce-related actions the user did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The body repeats an overbroad activation scope without clear boundaries or disambiguation criteria, increasing the chance that the skill is invoked for ordinary e-commerce discussion rather than a deliberate request to use Vipshop. In this skill, that ambiguity is more dangerous because activation can cascade into automatic login handling and command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger description is overly broad and includes common shopping-intent phrases, plus it claims coverage for competing platforms' promotion queries. In context, over-triggering is especially dangerous because the skill then attempts login checks, possible auto-installation, and external actions, causing a simple conversational mention to escalate into privileged behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The overview repeats broad trigger conditions without clear boundaries, increasing the chance that unrelated shopping queries invoke this skill. Because the skill's workflow includes checking local token files and potentially initiating login-related actions, broad matching materially raises the risk of unintended credential-adjacent operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to execute a script from a sibling skill directory (../vipshop-user-login/scripts/vip_login.py --blocking). Cross-skill script execution bypasses normal isolation boundaries, enables unexpected code execution outside the declared skill scope, and could be abused if the neighboring skill contents are modified or untrusted.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill advertises and orchestrates capabilities that imply file access, network access, shell/script execution, and credential handling, but it does not declare any explicit tool scope or permissions boundaries. In a skill ecosystem, missing scope declarations increase the chance of over-broad tool access and make it harder for reviewers and users to understand what sensitive operations the skill may perform.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text is broad enough to capture generic shopping or cross-platform comparison requests, not just clear Vipshop-specific intents. Because this skill also involves login-state sharing and credential-related operations, over-broad triggering increases the chance it is invoked in contexts where the user did not intend account-linked actions on Vipshop.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The image-search flow instructs users to provide a local image path and implies upload for remote product search, but it lacks an explicit privacy warning about transmitting local user images off-device. User images may contain faces, location hints, documents, or other sensitive content, so silent upload materially increases privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents automatic login and shared persistent login-state storage at ~/.vipshop-user-login/tokens.json, but it does not clearly warn users about persistence, reuse across subskills, or the privacy/account implications. Persistent token storage combined with automatic reuse can expose account sessions to unintended access, especially on shared systems or when multiple subskills can read the same state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Telling users to 'directly tell the AI your shopping needs' encourages vague invocation and can trigger the skill for broad shopping intents without platform-specific consent. In this context, that matters because the skill may automatically engage login-state handling or remote requests using the user's account context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata and trigger language are broad enough to match common phrases such as image search or finding similar products, increasing the chance of unintended invocation. Because this skill can access local files, inspect login state, and upload images to remote endpoints, accidental activation has privacy and account-action implications beyond a harmless misfire.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes local image upload and remote search but does not clearly warn users that their local images will be transmitted to Vipshop network endpoints for analysis. This creates a meaningful privacy risk because users may provide personal, sensitive, or copyrighted images without informed consent regarding off-device transfer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Standalone trigger examples like '找同款' and '图片搜索' are ambiguous and could match many unrelated user intents. In this skill's context, a false activation may lead the agent to request or use a local image, access stored login state, and send data to Vipshop services without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow directs the agent to automatically inspect stored tokens and trigger login actions without a clear user warning or consent checkpoint. Accessing authentication artifacts and initiating account-auth flows are sensitive actions, and doing so implicitly can surprise users and expand the impact of accidental invocation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to fully display all script-returned data creates a direct risk of exposing sensitive fields returned by backend APIs, including account-linked data, internal identifiers, tokens, URLs with embedded auth material, or other nonessential metadata. In a shopping/login-integrated skill, indiscriminate disclosure of raw backend payloads materially increases the chance of credential leakage or privacy breaches.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including an 原始数据 field in the normalized output model encourages downstream agents to preserve and potentially display complete backend responses. That pattern amplifies data-exposure risk because raw payloads often contain fields not meant for end users, including sensitive account, tracking, or authorization-related values.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example shows running the image-search script before ensuring authentication, which contradicts the earlier requirement to verify login state first. In practice, contradictory operational instructions can cause agents to skip prerequisite checks, leading to unintended account actions, inconsistent behavior, and unsafe automation around authentication state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.