Back to skill

Security audit

淘宝客全能工具箱

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly an affiliate-link conversion guide, but it includes operational-looking preset affiliate and API identifiers that could misattribute commissions or expose account/API data.

Review before installing. Replace every API key, SID, PID, and union ID with values from accounts you control, verify the final affiliate attribution before sharing generated links, and avoid using the JD/Pinduoduo HTTP endpoint unless the provider offers no safer alternative and you accept the exposure. Also inspect the referenced scripts separately because they were not included in this artifact.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Error
Location
SKILL.md:30
Finding

Preset Affiliate Identifiers Can Redirect User Commissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 30-37
Vulnerability Type: Affiliate commission hijacking through fixed attribution identifiers
Risk Level: High

bash
export JD_UNION_ID=1001703383
export TAOBAO_PID=mm_200970015_125850084_116244500128
export PDD_PID=8834451_187671353

Technical Analysis

The Skill describes generated links as belonging to the user, but its configuration instructions provide fixed JD, Taobao, and Pinduoduo affiliate identifiers. Affiliate conversion services use these identifiers to determine which account receives attribution and commission.

The document does not establish that these values belong to the installing user, require users to replace them, or disclose who controls them. Consequently, an agent following the instructions literally can generate links attributed to an unspecified third party.

This behavior is not necessary for the declared functionality. Link conversion requires affiliate identifiers, but least-privilege and attribution-integrity principles require them to be supplied explicitly by the authenticated user rather than embedded as global defaults.

Attack Path

  1. A user or agent installs the Skill and follows its configuration instructions.
  2. The fixed identifiers are written to ~/.openclaw/.env.
  3. A referenced conversion script reads those environment variables.
  4. The script submits a product link together with the preset affiliate identifier.
  5. The conversion provider generates a link attributed to the account controlling that identifier.
  6. A buyer follows the generated link and completes a transaction.
  7. The commission is credited to the preset identifier owner instead of the user.

Impact Assessment

The issue can cause unauthorized redirection of affiliate revenue across all conversions performed with the preset values. It does not, based on the reviewed file, grant operating-system privileges or access to the ...[truncated 179 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove every preset affiliate identifier from the distributed Skill.
  • Require users to enter identifiers obtained from their own authenticated affiliate dashboards.
  • Use clearly invalid placeholders such as YOUR_JD_UNION_ID; never use operational defaults.
  • Refuse to perform conversion until the user explicitly confirms the attribution identifier.
  • Display the effective platform and affiliate identifier before submitting each conversion request.
  • Store user-provided values in a permission-restricted secret store rather than silently modifying a shared environment file.
  • Document how users can verify resulting link attribution through each platform's official tools.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:26
Finding

Credential-Like API Key and Account SID Are Hardcoded in Public Configuration Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-28
Vulnerability Type: Hardcoded credentials
Risk Level: High

bash
export ZHETAOKE_APP_KEY=07d16b40e9c7485d8573f936173aa6d9
export ZHETAOKE_SID=41886

Technical Analysis

The Skill embeds an API-key-like value and account SID directly in its documentation and instructs users to place them in ~/.openclaw/.env. Anyone able to obtain the Skill can extract and reuse these values.

Even if the API key functions only as an application identifier, pairing it with a fixed SID creates cross-user attribution and abuse risks. If it provides authentication or quota access, public disclosure eliminates its confidentiality entirely. Writing shared values into a persistent environment file also unnecessarily broadens their exposure to other local processes or Skills that can read that file.

The declared conversion functionality requires access to an API, but it does not require distributing one user's live credentials to every installer.

Attack Path

  1. An attacker downloads or reads SKILL.md.
  2. The attacker extracts ZHETAOKE_APP_KEY and ZHETAOKE_SID.
  3. The attacker constructs requests to the documented Zhetaoke API.
  4. Requests are submitted under the embedded application or account identity.
  5. Depending on provider-side authorization, the attacker may consume quota, generate attributed links, access associated response data, or cause the account to be rate-limited or suspended.

A secondary local exposure path exists when users copy the values into ~/.openclaw/.env: any process with permission to read that file can recover and reuse them.

Impact Assessment

Potential impact includes unauthorized API consumption, quota exhaustion, account attribution abuse, rate limiting, service suspension, and exposure of activity associated with the embedded SID. The exact provider-side permissions cannot be established from the documentation ...[truncated 119 chars]

Remediation
View remediation

Remediation Suggestions

  • Immediately revoke or rotate the exposed API key if it is operational.
  • Remove the API key and SID from the repository and published Skill versions.
  • Require each user to obtain and supply credentials for an account they control.
  • Store credentials through the platform's dedicated secret-management mechanism.
  • Restrict any fallback environment file to the owning user, such as mode 0600.
  • Prevent logs, generated links, errors, and command output from exposing credentials.
  • Apply provider-side least-privilege scopes, per-user credentials, rate limits, and key rotation.
  • Add automated secret scanning to the release process.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:101
Finding

Sensitive Conversion Parameters Are Documented for Transmission over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 101-104
Vulnerability Type: Plaintext transmission of credentials and affiliate data
Risk Level: High

text
http://api.zhetaoke.com:20000/api/open_gaoyongzhuanlian_tkl_piliang.ashx
Required parameters: appkey, unionId, tkl

Technical Analysis

The documented JD and Pinduoduo conversion endpoint uses unencrypted HTTP. Requests to this endpoint carry an API key, affiliate union identifier, and user-supplied product link or token. HTTP provides neither transport confidentiality nor authenticated integrity.

An attacker with a suitable network position can observe these values or alter the request and response. In particular, a modified API response could replace the legitimate generated affiliate link with an attacker-controlled destination or attribution link.

Plaintext transport is unnecessary for the declared functionality when a correctly authenticated HTTPS endpoint is available. It violates least exposure by disclosing credentials and conversion metadata to every intermediary capable of observing the connection.

Attack Path

  1. The user submits a JD or Pinduoduo link for conversion.
  2. The implementation follows the documented endpoint and sends appkey, unionId, and tkl over HTTP.
  3. An attacker on the same network, a compromised proxy, or another network intermediary intercepts the request.
  4. The attacker records the credentials and user data or modifies the request.
  5. The attacker can also alter the response and substitute a malicious or differently attributed promotion link.
  6. The user receives or distributes the substituted link, enabling traffic diversion, commission theft, or redirection to an unsafe destination.

Impact Assessment

An attacker may obtain the API key, affiliate identifier, submitted shopping links or tokens, and conversion metadata. Active interception can modify generated links and redirect users o ...[truncated 201 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the endpoint with an official HTTPS endpoint.
  • Require certificate and hostname validation and reject invalid certificates.
  • Do not permit automatic fallback from HTTPS to HTTP.
  • Prefer authorization headers or protected request bodies over URL query parameters for credentials.
  • Rotate credentials previously transmitted over plaintext.
  • Validate returned URLs against an explicit allowlist of expected domains and HTTPS schemes.
  • Display the final destination and affiliate attribution before distributing a generated link.
  • If the provider does not support secure transport, disable this integration rather than transmitting sensitive parameters over HTTP.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level description advertises '自动价保' and '佣金追踪' as core functions, and the dependency list references a JD price-protect skill, but the usage section only exposes conversion scripts such as taobaoke_master.py, convert_all_platforms.py, taobao_convert_v2.py, and jd_batch_convert.py. This creates an intent/documentation divergence because the documentation presents those capabilities as part of this skill even though the described executable surface is limited to affiliate link conversion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes sending user-supplied product links plus affiliate identifiers such as appkey, sid, pid, and unionId to third-party APIs, but does not clearly warn users that this data leaves the local environment. This weakens informed consent and can lead to unintended disclosure of browsing intent, affiliate/account metadata, and potentially sensitive commercial tracking information to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions, usage guidance, and warnings are all written in Chinese, which effectively forces a specific language for users of the skill. The file does not offer an alternative language, opt-in, or justification that this is a region-specific or Chinese-only tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.