Back to skill

Security audit

男装电商系统

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent e-commerce project generator, but its templates include unsafe defaults such as hardcoded secrets, default administrator credentials, and weak password-handling guidance.

Install only if you treat the output as a prototype or teaching scaffold. Before using any generated code beyond local development, replace all sample credentials and JWT secrets, remove default accounts, avoid root database access, hash passwords rather than reversibly encrypting them, restrict database users and hosts, review token storage, and add warnings/confirmations around destructive database and API operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-project.sh:300
Finding

Generated Application Uses a Hardcoded MySQL Root Password

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-project.sh:361
Finding

Generated JWT Tokens Use a Publicly Known Static Signing Secret

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/database-schema-continued.md:149
Finding

Database Template Publishes a Predictable Administrator Account

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/database-schema-continued.md:311
Finding

Database Security Guidance Creates Remotely Accessible Users with Fixed Passwords

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/database-schema-continued.md:326
Finding

Template Recommends Reversible Password Encryption with a Hardcoded Key

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/frontend-architecture.md:555
Finding

Authentication Bearer Tokens Are Persisted in Script-Accessible Local Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/backend-architecture.md (reported line 611)May include surrounding context.

md
GET    /api/users/{id}      # 获取用户详情
POST   /api/users           # 创建用户
PUT    /api/users/{id}      # 更新用户
DELETE /api/users/{id}      # 删除用户

# 商品相关
GET    /api/products        # 获取商品列表

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/backend-architecture.md (reported line 618)May include surrounding context.

md
GET    /api/products/{id}   # 获取商品详情
POST   /api/products        # 创建商品
PUT    /api/products/{id}   # 更新商品
DELETE /api/products/{id}   # 删除商品

# 订单相关
GET    /api/orders          # 获取订单列表

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The encryption example stores passwords in a reversibly encrypted form and demonstrates decrypting and returning them, which is fundamentally unsafe for authentication data. Passwords must never be recoverable; if this pattern is implemented, compromise of the key or database exposes all user passwords and enables account takeover across reused credentials.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/frontend-architecture.md (reported line 79)May include surrounding context.

md
│   │       └── UserMgr.vue     # 用户管理
│   ├── App.vue                 # 根组件
│   └── main.js                 # 入口文件
├── .env                        # 环境变量
├── .env.development            # 开发环境变量
├── .env.production             # 生产环境变量
├── vite.config.js              # Vite配置

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/frontend-architecture.md (reported line 80)May include surrounding context.

md
│   ├── App.vue                 # 根组件
│   └── main.js                 # 入口文件
├── .env                        # 环境变量
├── .env.development            # 开发环境变量
├── .env.production             # 生产环境变量
├── vite.config.js              # Vite配置
├── package.json                # 项目配置

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/frontend-architecture.md (reported line 81)May include surrounding context.

md
│   └── main.js                 # 入口文件
├── .env                        # 环境变量
├── .env.development            # 开发环境变量
├── .env.production             # 生产环境变量
├── vite.config.js              # Vite配置
├── package.json                # 项目配置
└── README.md                   # 项目说明

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill title and the entire README are written in Chinese, and the document does not mention any ability for the user to choose another language or locale. Under the policy, a skill that implicitly enforces a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill references shell scripts and project-generation scripts but does not declare any tool scope or permissions boundaries. In a skill that can touch the filesystem and potentially execute shell commands, missing explicit restrictions increases the chance of overbroad or unintended command execution, especially if downstream runners infer capabilities from repository contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is written as a directive in Chinese and presents the behavior in a single language without indicating that users may choose another language. Under the language/locale policy, forcing one language without opt-in is a natural-language policy issue unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is designed to generate payment, authentication, deployment, and security-sensitive application code, yet it does not warn users about the risks of using generated code without security review. In this context, omission of warnings is dangerous because users may deploy insecure JWT, payment callback, or infrastructure configurations directly into production.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A broad trigger condition can cause the skill to activate in contexts beyond narrowly requested e-commerce scaffolding, including prompts involving payments, auth, deployment, or adjacent coding tasks. Overbroad activation raises the risk of the skill offering sensitive code or invoking risky helper behavior without sufficient user intent or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example instructs users to run mysql -u root -p < database/init.sql against a local MySQL instance without any warning that the script can create, drop, or overwrite schema/data in the selected database. In a code-generation skill that encourages quick setup, this can lead users to execute destructive initialization steps on the wrong environment, causing accidental data loss or corruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents a DELETE endpoint for removing orders and shows a successful response, but it does not include any warning about data loss, irreversibility, or the impact on user records. For markdown files, destructive behaviors that could affect user data or system integrity should be accompanied by user-facing warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The API spec describes deleting an address with a successful response but provides no caution that this removes stored personal/shipping information. In markdown documentation, actions affecting user data should explicitly warn users about the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The DELETE product endpoint removes product data, yet the documentation does not mention that the action is destructive or potentially irreversible. For markdown files, SQP-2 applies when descriptions omit warnings about operations that may affect system integrity or user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes a destructive operation to clear the shopping cart, but it provides no warning about data loss, confirmation expectation, or irreversible effects. Under the markdown-specific SQP-2 criteria, behaviors affecting user data should include some cautionary disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file title and all user-facing documentation are written exclusively in Chinese, which imposes a specific language on readers without any stated opt-in, alternative language option, or region-specific justification. This matches the policy category for language/locale constraints expressed in natural language.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/database-schema-continued.md (reported line 133)May include surrounding context.

md
-- 订单配置
('order_auto_cancel_minutes', '30', '订单自动取消时间(分钟)', 'order'),
('order_auto_confirm_days', '7', '订单自动确认收货时间(天)', 'order'),
('order_auto_complete_days', '3', '订单自动完成时间(天)', 'order'),

-- 支付配置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains a shell backup script that automatically deletes backup files older than 7 days using find ... -delete. While the script prints a completion message, there is no warning in the surrounding documentation that running it will permanently remove existing backups, which could affect data retention and recovery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The maintenance SQL includes DELETE statements that remove orders older than 3 months and stale cart data. In a markdown skill/documentation file, destructive data operations should be accompanied by a clear warning about data loss, backup expectations, and execution caution, but no such warning is present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance says to grant only necessary permissions, but the example creates database users bound to '%' and gives the application account broad read/write access to the entire schema. In a production ecommerce system, exposing remotely accessible credentials with full CRUD over all business data increases blast radius if the app, network perimeter, or credentials are compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.