Back to skill

Security audit

唯品会商品详情

Security checks for vulnerabilities and agentic risk

Overview

This skill can expose a logged-in Vipshop session through generated product links and automatically install or run a separate login skill.

Install only after the publisher removes token-bearing auto-login links, stops printing or returning session material, and gates any login-skill installation behind explicit approval with a pinned, reviewed dependency. A plain product-detail skill should return product data and ordinary product URLs, not reusable login links built from local account tokens.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/exchange_link_builder.py:145
Finding

Vipshop Access Token Exposed in Generated Output URL

Content
View full analysis
str: """ 获取 secret key Returns: secret key 字符串 """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ```python def _get_token() -> str: """ 从 token 文件获取 PASSPORT_ACCESS_TOKEN 参考 search.py 的 load_login_tokens 方法 Returns: token 字符串,如果未获取到则返回空字符串 """ log("=" * 50) log("开始获取 token...") token_file = Path.home() / ".vipshop-user-login" / "tokens.json" log(f"token 文件路径: {token_file}") if not token_file.exists(): log(f"❌ token 文件不存在: {token_file}") return "" log("✅ token 文件存在") try: with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) log(f"✅ 成功读取 token 文件") log(f" 数据类型: {type(data)}") if data and isinstance(data, dict) and 'cookies' in data: log("✅ 数据格式正确,包含 cookies 字段") expires_at = data.get('expires_at') log(f" expires_at: {expires_at}") if expires_at and time.time() > expires_at: log("❌ token 已过期") return "" cookies = data.get('cookies', {}) log(f" cookies 数量: {len(cookies)}") log(f" cookies 键: {list(cookies.keys())}") token = cookies.get("PASSPORT_ACCESS_TOKEN", "") if token: log(f"✅ 成功获取 PASSPORT_ACCESS_TOKEN") log(f" token 长度: {len(token)}") log(f" token 前10位: {token[:10]}...") return token else: log("❌ cookies 中不存在 PASSPORT_ACCESS_TOKEN") return "" else: ...[truncated 5196 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:116
Finding

Automatic Installation and Execution of an Unpinned External Login Skill

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation adds device-ID generation and local persistence while claiming to be a simple product lookup skill, that is a meaningful scope expansion beyond user expectations. Hidden persistence tied to account or device identity can enable tracking, stateful profiling, or later misuse of session-related data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation adds device-ID generation and local persistence while claiming to be a simple product lookup skill, that is a meaningful scope expansion beyond user expectations. Hidden persistence tied to account or device identity can enable tracking, stateful profiling, or later misuse of session-related data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation adds device-ID generation and local persistence while claiming to be a simple product lookup skill, that is a meaningful scope expansion beyond user expectations. Hidden persistence tied to account or device identity can enable tracking, stateful profiling, or later misuse of session-related data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation normalizes returning auto-login URLs containing exchange-token parameters directly to the user. Such links are session-sensitive artifacts that can grant account access if exposed in logs, chat history, screenshots, or to the wrong recipient.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Directing the AI to reveal an exchange-token auto-login URL is a clear sensitive-data exposure issue. Anyone who obtains the response may be able to replay the link to access the user's authenticated session or pivot into account actions.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions explicitly tell the AI not to distinguish tokenized auto-login links from normal links and to display them openly. That removes any safeguard around highly sensitive session material and increases the likelihood of accidental disclosure through transcripts and downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the AI to automatically install software and initiate account login flows without a strong, explicit warning or consent gate for system-changing and account-affecting behavior. In context, this is more dangerous because it combines package installation, blocking execution, and authentication handling under an innocuous shopping workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Authorizing execution of a sibling skill's script bypasses normal skill isolation and trust boundaries. A product-detail skill should not directly invoke arbitrary code from another directory, especially for login handling, because this can execute unreviewed logic with access to local credentials and files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code hardcodes a signing secret and implements HMAC-MD5 signing for token exchange links. Embedding a reusable secret in client-side skill code exposes a sensitive credential to anyone with code access and enables unauthorized generation of signed exchange requests, which is unrelated to simple product-detail lookup and materially increases account/session abuse risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest context and README describe querying full product details including规格尺码、品牌介绍、用户评价、库存等, but the README also states that the auxiliary-information API is currently unavailable and only main product information is returned. Because the documented workflow and interface section acknowledge that auxiliary information such as size-related data is not currently provided, the skill's stated behavior overpromises compared with what the implementation is described to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes reading local login tokens and using them to authenticate requests to external VIPShop APIs, but does not provide a clear privacy and credential-handling warning. This is dangerous because users may not realize local authentication artifacts and cookies are being accessed and transmitted, which can expose sensitive session data or violate least-expectation principles.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs the agent to automatically install and execute another skill, expanding scope from product lookup into system modification and secondary code execution. This is dangerous because it creates a supply-chain and consent problem: a user asking for product details may trigger package installation and execution of additional code they did not explicitly approve.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Allowing automatic installation and invocation of another skill without a prominent upfront warning enables unexpected system changes and execution of external logic. In an agent ecosystem, this broadening of authority is risky because it can be abused to chain into unreviewed skills or surprise users with actions beyond the stated purpose of viewing product details.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs file access, possible file creation/modification, and networked actions, but declares no tool/permission scope. That weakens policy enforcement and makes it easier for an agent to overreach into local files or network operations without explicit review. In this context, the undocumented access is especially concerning because the skill also interacts with login state and token material.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly states support for querying via 商品ID or 商品链接, and the overview repeats that claim. However, the documented execution flow only says '接收用户提供的商品ID' and runs python3 scripts/detail.py <product_id>, with no parsing or conversion flow for product URLs. This is an active intent/behavior mismatch within the documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description says the skill triggers when users want to view product details and lists broad examples such as '看商品详情', '看商品图片', '查活动优惠', and '确认库存', followed by '包括但不限于'. This creates an ambiguous and expansive trigger scope without clear boundaries or exclusion conditions, increasing the chance of unintended activation during ordinary shopping-related conversation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to install another skill via package management during normal execution. That expands trust to an additional package and introduces supply-chain and privilege-expansion risk unrelated to a basic product-detail query.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code forwards authentication cookies and the device identifier (mars_cid) to a remote API, enabling access tied to the user's logged-in session. In this skill context that is expected for authenticated product-detail retrieval, so the behavior is not inherently malicious, but the lack of explicit user-facing disclosure, minimization, and guardrails increases privacy and session-handling risk if reused, logged, or redirected improperly elsewhere in the skill chain.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script goes beyond read-only product-detail retrieval by generating authenticated exchange-token links using a local login token and a signing secret. In the context of a product-detail skill, that creates an unnecessary capability to transform local session state into portable authenticated URLs, which could be abused for session bridging, unauthorized account access flows, or covert token handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently reads a sensitive local token file from the user's home directory and extracts PASSPORT_ACCESS_TOKEN without any user-facing notice or confirmation. Even if intended to support login reuse, this behavior accesses credential material in a way that is not necessary for a nominal product-detail query and increases the risk of unintended credential use or exfiltration through downstream link generation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for querying VIP product details, while this module implements persistent device-identity storage under the user's home directory. Creating and saving a device identifier may be useful to support login flows, but that stateful local persistence is not justified by the stated product-detail retrieval purpose of this skill file itself.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Early sections advertise detailed outputs such as images,优惠券、精华评论 and broad detail coverage, while line L025 and later L347-L349 state the auxiliary-information interface is unavailable and only main product information is returned. This is an active contradiction within the documentation about what the implementation can currently deliver, not merely an omission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The module docstring says the tool queries product information and then 进行分析总结, implying substantive analysis or summarization. The analyze_product_info function mainly selects fields, rewrites image URLs, and reshapes API response data into a smaller JSON object rather than performing genuine analytical processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTTP header forces 'Accept-Language' to prefer 'zh-CN' and Chinese content, which is a natural-language locale decision embedded in the code. There is no indication in this file that the user can opt into or override that locale preference.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest states the skill supports querying via 商品ID或商品链接. In this file, the CLI entrypoint and main retrieval function only take a single product_id argument and pass it directly into detail APIs, with no code to detect, validate, or extract an ID from a product URL.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.