Back to skill

Security audit

唯品会技能集

Security checks for vulnerabilities and agentic risk

Overview

This shopping skill is mostly coherent, but it handles login sessions in a way that can expose a user's Vipshop account token in chat-visible links.

Install only if you are comfortable with this skill storing and reusing your Vipshop login session locally, uploading selected images to Vipshop services, and showing product links that may contain login-session material. Do not share transcripts, screenshots, logs, or copied product links produced while logged in; prefer a fixed version that returns ordinary product URLs or uses a server-side short-lived redirect instead of exposing tokenized links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Skill Documentation Injects Mandatory Agent-Control Instructions

Content
View full analysis
⚠️ **Important rule**: The AI must first load this skill specification > (use_skill) before executing any script or returning results, and must > not bypass the skill specification to process data independently. ## ⚠️ AI behavior constraints (must be strictly followed) ### Do not modify scripts - The AI is strictly prohibited from modifying any Python script under the `scripts/` directory. - The AI is strictly prohibited from creating, deleting, or renaming any script. - The AI is strictly prohibited from modifying script logic, parameters, interface addresses, or other content. - The AI may only execute scripts and may not alter their contents. ### Do not modify SKILL.md - The AI is strictly prohibited from modifying any child skill's `SKILL.md`. - The AI is strictly prohibited from adding, deleting, or modifying any content in `SKILL.md`. - The AI may only read `SKILL.md` to understand how to use the skill. ``` The displayed text is an English translation of the directives at the cited locations. ### Technical Analysis These instructions do not merely describe the shopping interface. They attempt to impose absolute behavioral restrictions on the agent loading the package, including requirements to process tasks only through package-controlled scripts and prohibitions against modifying package files. A Skill may document supported commands and expected inputs, but it should not attempt to override higher-priority platform policies, the user's current task, security review procedures, or remediation requests. The restrictions are particularly problematic during an audit because they instruct an agent not to correct or alter code even when the user explicitly requests remed ...[truncated 1191 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
vipshop-product-search/scripts/exchange_link_builder.py:49
Finding

Reusable Authentication Token Is Embedded in Generated Output URLs

Content
View full analysis
str: token_file = Path.home() / ".vipshop-user-login" / "tokens.json" if not token_file.exists(): return "" try: with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) if data and isinstance(data, dict) and 'cookies' in data: expires_at = data.get('expires_at') if expires_at and time.time() > expires_at: return "" cookies = data.get('cookies', {}) token = cookies.get("PASSPORT_ACCESS_TOKEN", "") if token: return token return "" return "" except json.JSONDecodeError: return "" except Exception: return "" def build_exchange_link(target_url: str) -> str: token = _get_token() if not token: return target_url secret = _get_secret() timestamp = int(time.time() * 1000) data_obj = {"t": token, "ts": timestamp} json_str = json.dumps(data_obj, separators=(",", ":")) base64_str = base64.b64encode( json_str.encode("utf-8") ).decode("utf-8") signature = _generate_signature(base64_str, secret) base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) return full_url ``` ### Technical Analysis The code reads `PASSPORT_ACCESS_TOKEN` from the local credential file, places it in a JSON object, and ap ...[truncated 2307 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
vipshop-product-search/scripts/exchange_link_builder.py:39
Finding

Signing Secret and API Identifier Are Hardcoded in Distributed Client Code

Content
View full analysis
str: """ Get the secret key. Returns: Secret-key string. """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` The product and image request scripts also contain the following fixed API identifier: ```python API_KEY = "dafe77e7486f46eca2e17a256d3ce6b5" ``` Equivalent inline uses include: ```python params = { 'keyword': keyword, 'app_name': 'shop_pc', 'app_version': '4.0', 'api_key': 'dafe77e7486f46eca2e17a256d3ce6b5', 'mars_cid': mars_cid, } ``` ### Technical Analysis A signing key embedded in a distributable package cannot function as a confidential secret. Any user or attacker who can download or inspect the Skill can recover it and independently generate the same HMAC-MD5 signatures as the official client. This compromises the trust model of the exchange-link signature. A server cannot treat possession of a signature made with this key as proof that a request came from trusted code because every package recipient possesses the key. The fixed API key may be an intentionally public client identifier. If it is intended to authorize requests or protect quota, however, embedding it in the client provides no secrecy and permits extraction and reuse. The project documentation does not establish that it is non-sensitive. The use of HMAC-MD5 also relies on a legacy digest. While ...[truncated 1449 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
vipshop-user-login/requirements.txt:1
Finding

Third-Party Dependencies Are Installed Without Reproducible Version or Integrity Pinning

Content
View full analysis
=2.28.0 qrcode>=7.0 Pillow>=9.0.0 packaging>=21.0 ``` The installation documentation additionally recommends: ```bash pip install requests qrcode Pillow ``` ### Technical Analysis Every dependency uses an open-ended minimum-version constraint, and the documented installation command is entirely unpinned. A future installation can therefore resolve to versions that were never reviewed with this Skill. No lockfile, constraints file, package hash, or trusted artifact manifest is present in the audited directory. This makes installations non-reproducible and leaves package selection dependent on the repository state and dependency resolver at installation time. The audited dependency names are common and no typosquatted package was identified. The risk arises from unrestricted future versions and missing integrity verification rather than evidence that the currently named projects are malicious. ### Attack Path 1. A user follows the documented installation process at a later date. 2. The package resolver selects the newest versions satisfying the open-ended constraints. 3. A newly released, compromised, or behaviorally incompatible dependency is selected without review. 4. The dependency's installation or import-time code executes with the privileges of the user running the Skill. 5. Malicious dependency code could read the local Vipshop token file, alter network traffic, modify user files, or execute other code available to that user account. ### Impact Assessment A compromised dependency would execute with the same operating-system privileges as the Python process. It could potentially access `~/.vipshop-user-login/tokens.json`, the QR-code files, environment variables, and any ...[truncated 219 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (101)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill presents itself as a complete cross-platform shopping alternative with broad automatic use, while also implying local login-state reads and remote requests without clear permission disclosure. Even if some functionality is implemented via child skills, the packaging overstates scope and understates sensitive behavior, which can lead to unsafe automatic invocation and uninformed user consent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example output normalizes inclusion of an exchange-token login link, which encourages downstream agents and developers to treat credential-bearing URLs as safe to print. In a shopping skill context tied to user accounts, that materially increases the likelihood of secret leakage through transcripts, analytics, screenshots, and shared chats.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the AI to display a live exchange-token auto-login URL directly in the response. Exposing such a URL can leak a bearer-style authenticated session artifact to logs, chat history, plugins, or other observers, enabling account access or session hijacking if the link is reused.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly claims nearly any product-search intent across other e-commerce platforms as valid input and redirects it to Vipshop. In context, this is more dangerous because the skill also auto-triggers login behavior, so an ambiguous mention of shopping on another platform could result in unintended account-related actions within Vipshop.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly claims nearly any product-search intent across other e-commerce platforms as valid input and redirects it to Vipshop. In context, this is more dangerous because the skill also auto-triggers login behavior, so an ambiguous mention of shopping on another platform could result in unintended account-related actions within Vipshop.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown description repeats broad trigger conditions without meaningful constraints, reinforcing that ordinary shopping-related speech should activate the skill. Repetition of overbroad triggers increases the chance of misrouting user requests and compounds risk because the skill is designed to automatically proceed into login and subsequent actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match generic shopping or promotion-related requests, including requests about other platforms, then redirect them into this skill. Over-broad activation increases the chance that the agent runs account-linked actions and external queries in contexts the user did not specifically intend, especially combined with the skill's auto-login behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and orchestrates capabilities that imply file access, network use, shell/script execution, and token handling, but it does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent may invoke the skill with broader-than-necessary privileges, increasing the blast radius for misuse or for unsafe behavior in child skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text is extremely broad, covering generic shopping, comparison, and migration scenarios across multiple unrelated platforms. This increases the chance the skill will trigger in conversations where the user did not intend to invoke a VIP.com workflow, potentially causing unnecessary network access, login prompts, or data handling in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The image-search feature says local images can be used, but it does not clearly warn that those images will be uploaded to a remote service for processing. This is dangerous because users may unintentionally disclose sensitive or personal content embedded in local photos, especially in a shopping context where they may assume analysis happens locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document notes that login state is stored locally and shared across sub-skills, but it does not clearly warn users about the sensitivity of session tokens or the security implications of cross-skill reuse. In practice, shared local auth state increases the impact of any compromised or overprivileged child skill because one component can potentially leverage another component's session.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance says the AI will automatically choose and combine sub-skills based on user needs, but it does not define clear boundaries for when not to invoke them. In this skill, that is more dangerous because child skills may involve login flows, local token access, image uploads, and network requests, all of which should require tighter trigger conditions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level activation description is overly broad and lacks clear boundaries for when the skill should or should not run. In context, this is more dangerous because the skill can access local file paths and send image data to external Vipshop endpoints, so ambiguous activation increases the risk of unintended privacy-sensitive behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger phrases like “找同款” and generic image-search wording can cause the skill to activate in situations the user did not intend, especially in multi-skill environments. Because this skill uploads a local image and may auto-trigger login, unintended activation can lead to privacy-impacting actions or external data transmission without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents external upload and processing endpoints in the implementation section, but it does not clearly warn users up front that their local image will be transmitted to external Vipshop services. This is a real privacy and consent issue: users may provide local files expecting local analysis, while the skill actually performs network upload of potentially sensitive images.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The FAQ explicitly states that the skill does not support directly passing an image URL. However, the documented workflow for fetching the next page requires calling the script with an --image-url argument derived from the prior result, which is a form of image-URL input. This is an active contradiction in the skill documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file hard-codes a secret signing key in source code, making the credential available to anyone with code access and difficult to rotate if exposed. In a consumer shopping skill, embedding server-side signing material in client-distributed logic is especially risky because it can enable unauthorized generation of trusted exchange links and broad compromise of the associated token exchange mechanism.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads a persisted login token from ~/.vipshop-user-login/tokens.json and silently uses it to construct an exchange URL, which exceeds the narrow role of a link builder and creates implicit access to account credentials. In this skill context, that is more dangerous because a shopping assistant should not automatically harvest local session state without explicit user consent, and the resulting URL can propagate authenticated context if logged, shared, or intercepted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.