Back to skill

Security audit

唯品会

Security checks for vulnerabilities and agentic risk

Overview

This Vipshop shopping skill should go to Review because it automatically pushes users into login and can expose saved account tokens inside links it asks the agent to display.

Install only if you are comfortable with this skill storing your Vipshop login cookies locally, reusing them across subskills, uploading selected images to Vipshop services, and producing product links that may contain account-session material. Avoid sharing generated links or transcripts, and prefer a revised version that removes tokens from URLs and asks before login, install, and upload actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
vipshop-product-detail/scripts/exchange_link_builder.py:40
Finding

Reusable access token exposed through generated product URLs

Content
View full analysis
str: return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ```python token_file = Path.home() / ".vipshop-user-login" / "tokens.json" with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) cookies = data.get('cookies', {}) token = cookies.get("PASSPORT_ACCESS_TOKEN", "") ``` ```python timestamp = int(time.time() * 1000) data_obj = {"t": token, "ts": timestamp} json_str = json.dumps(data_obj, separators=(",", ":")) base64_str = base64.b64encode( json_str.encode("utf-8") ).decode("utf-8") signature = _generate_signature(base64_str, secret) base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) return full_url ``` ### Technical Analysis The `PASSPORT_ACCESS_TOKEN` is read from the locally protected login-state file and inserted into a JSON object under the `t` property. That object is only Base64-encoded before being placed in the `dt` query parameter. Base64 is a reversible transport encoding and provides no confidentiality. Anyone who receives a generated product URL can URL-decode and Base64-decode `dt` to recover the underlying access token. The HMAC signature does not protect token confidentiality. Moreover, the signing secret is hardcoded in every copy of the builder, so possession ...[truncated 1930 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Skill instructions override agent safety discretion and force authentication behavior

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
vipshop-user-login/requirements.txt:1
Finding

Third-party dependencies are not reproducibly pinned or integrity verified

Content
View full analysis
=2.28.0 qrcode>=7.0 Pillow>=9.0.0 packaging>=21.0 ``` The Skill documentation also recommends direct package installation: ```bash pip install requests qrcode Pillow ``` ### Technical Analysis All dependencies use open-ended lower bounds. A future installation can therefore resolve to package versions that did not exist and were not reviewed when the Skill was audited. No lock file, package hash, upper bound, or approved package-index configuration is provided. The identified package names are legitimate and the audit found no evidence that they are intentionally malicious. The issue is that dependency resolution is non-reproducible and does not verify artifact integrity. Python package installation may execute build backend or installation-related code. Consequently, silently resolving to an unexpected or compromised future package release can introduce code execution into the login environment. ### Attack Path 1. A user follows the installation instructions or installs from `requirements.txt`. 2. The package resolver queries its configured package index. 3. Because only lower bounds are present, it selects the newest versions satisfying those bounds. 4. A compromised, malicious, or incompatible future release is selected without review. 5. Package build or import behavior executes in the user's environment. 6. The dependency may gain the same access as the login process, including potential access to QR state and locally stored authentication cookies. This is a supply-chain exposure rather than evidence of an existing malicious dependency. ### Impact Assessment A compromised dependency would execute with the privileges of the user running ...[truncated 396 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (102)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The package is advertised as a complete multi-skill shopping assistant, but the flagged behavior suggests some capabilities may actually reduce to login-state reuse or link construction rather than the promised functions. This is risky because users may grant trust and permissions based on the broader shopping framing while hidden authentication/session behavior does the real work.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
2. 创建 `SKILL.md` 文件,包含完整的技能说明

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script hardcodes a secret key used to generate HMAC-signed exchange-token links. Embedding secrets in source code makes them recoverable by anyone with code access and enables unauthorized reproduction of authenticated link generation, undermining trust boundaries around the exchange endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the AI to display automatic-login URLs containing exchange tokens directly to the user without any privacy warning or masking. Such URLs can function as bearer secrets; if exposed in chat logs, screenshots, browser history, or to another party, they may enable unauthorized account access or session hijacking.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Directly revealing exchange-token login links exposes authentication material as part of normal output. Because these links can auto-authenticate the holder, disclosure turns a product-detail response into credential leakage with immediate account-access implications.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The output rules require the AI to always show tokenized login links and to treat them the same as ordinary links, removing any safety distinction around credential-bearing URLs. This materially increases the chance of sensitive-token disclosure through transcripts, logs, copy/paste, link previews, and third-party observation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Directing the agent to run clawhub install vipshop-user-login during normal search flow is dangerous because it authorizes package installation from skill content rather than from trusted system policy. A user asking to search products did not authorize software installation, and this behavior could be abused to introduce unreviewed code or additional permissions into the environment.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger description is extremely broad and claims shopping-related intents across many platforms, making accidental or overbroad activation likely. In context, that is dangerous because activation can lead to login prompting, dependency installation, and local script execution, so a casual shopping utterance could trigger higher-risk behavior than the user expected.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The overview repeats ambiguous activation conditions without meaningful constraints, reinforcing over-triggering risk. Given the skill's ability to auto-initiate login flow and invoke other components, this ambiguity materially increases the chance of surprising actions being taken from ordinary shopping conversation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates automatic installation of another skill and execution of shell/Python commands without adequate warning that the agent will modify the local environment and run code. This is dangerous because users asking for promotion information would not reasonably expect software installation or local command execution, creating a strong consent and supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code logs the qrToken during login continuation and success/failure paths, and elsewhere also logs authentication-related values. A qrToken is a live authentication session artifact and can enable unauthorized polling or hijacking of the login flow if logs are exposed to operators, other tenants, telemetry backends, or support tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script persists authentication cookies locally through TokenManager after successful login. Stored access tokens are bearer secrets; if the local token store is readable by other users, malware, backups, or logs, an attacker may reuse them to impersonate the user until expiry.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises and orchestrates capabilities that imply file access, network access, shell/script execution, and credential handling, but it does not declare any explicit tool scope or permission boundaries. In a skill ecosystem, missing least-privilege declarations increases the chance that the agent can invoke sensitive capabilities or access local state without clear user consent or platform enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger language is broad enough to match generic shopping or comparison-shopping requests across many platforms, which can cause the agent to invoke this skill in situations where the user did not specifically ask for Vipshop. Over-broad activation increases the chance of unnecessary login prompts, image uploads, network requests, or credential reuse outside the user's intended context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill supports image-based search but does not clearly warn users that their local images will be transmitted to a remote service for analysis. Images can contain sensitive personal information or metadata, so failing to disclose this data flow undermines informed consent and creates avoidable privacy exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation says login is automatically triggered and shared across subskills, and separately states that tokens are stored at a persistent filesystem path, but it does not clearly warn users about ongoing storage and reuse of authenticated state. Persistent shared sessions raise privacy and account-security concerns because later actions may occur under a cached login without fresh user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The FAQ suggests generic phrases like shopping-related requests as invocation cues, which can make the skill activate implicitly without clear informed intent. In a skill that can trigger login workflows and persistent session reuse, vague activation guidance increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are overly broad and can cause unintended invocation of the skill in normal conversation. In this skill, unintended invocation is more dangerous because it can lead to login checks, account actions, and local image handling/network upload without the user clearly intending to use the Vipshop workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to automatically trigger login and upload a local image to external Vipshop endpoints without an explicit user-facing consent step. This creates a real privacy and safety risk because a loosely triggered skill could transmit local user content and initiate account-related flows without informed approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.