Back to skill

Security audit

闲鱼商品精选助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xianyu marketplace search helper, but it automatically saves local search-history records without clear opt-in, retention, or deletion controls.

Review this skill before installing if you do not want your marketplace searches, price interests, and listing links saved in local memory. Prefer using it only after disabling or removing the automatic history-writing behavior, or after adding clear opt-in and deletion controls. Also treat broad activation phrases as potentially ambiguous and confirm before running searches from casual Xianyu-related questions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Note
Location
SKILL.md:383
Finding

Automatic Persistent Logging of User Search Activity

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:383-393
Vulnerability Type: Unnecessary persistent activity logging
Risk Level: Low

Complete Vulnerable Snippet:

markdown
搜索完成后自动记录到 `memory/YYYY-MM-DD.md`:

```markdown
### 闲鱼搜索记录

**时间:** 2026-03-10 18:36
**关键词:** RTX 5090
**结果数量:** 10 条
**价格区间:** ¥1.74 万 - ¥1.90 万
**最低价商品:** [技嘉魔鹰 OC](https://www.goofish.com/item?id=1017187960312)
**筛选条件:** 个人闲置/单一价格/排除商家
text

### Technical Analysis

The Skill instructs the Agent to automatically write every completed search to a persistent daily memory file. The retained data includes the search timestamp, user query, price range, selected listing URL, result count, and filtering preferences.

Persisting this information is not necessary for the Skill's primary function of searching for marketplace listings and returning results. The instruction provides no consent mechanism, opt-out option, data-minimization policy, retention period, access restriction, or deletion process. Consequently, potentially sensitive purchasing interests and preferences may accumulate across sessions.

This behavior is not classified as Agent Memory Poisoning because the retained content is activity history rather than attacker-controlled instructions intended to alter future Agent behavior.

### Attack Path

1. A user submits a marketplace query that may reveal a sensitive interest, purchasing intention, budget, or location preference.
2. The Skill performs the search and applies the requested filters.
3. After completing the search, the Skill automatically writes the query and associated result metadata to `memory/YYYY-MM-DD.md`.
4. The records persist beyond the current invocation.
5. Any workspace component or user with permission to read that memory location may later inspect the retained search history.

No external exfiltration path or unauthorized privilege gain was identified.

### Impact Assessment

The iss
...[truncated 458 chars]
Remediation
View remediation

Remediation Suggestions

  1. Disable persistent search-history logging by default.
  2. Obtain explicit user consent before storing any query or result metadata.
  3. Provide a clear per-search opt-out and a global configuration option to disable history.
  4. Apply data minimization by omitting exact queries, direct listing links, timestamps, locations, and price preferences unless specifically required.
  5. Define a short retention period and automatically delete expired records.
  6. Provide users with commands or documented procedures to inspect and delete stored history.
  7. Restrict access to stored records using the narrowest available filesystem permissions.
  8. Avoid persisting searches identified as sensitive; when history is needed, prefer a redacted or aggregated record.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although the title includes an English label, the operational description, trigger phrases, usage examples, parameters, outputs, and error messages are written in Chinese and require Chinese-language commands such as 闲鱼搜索. There is no opt-in, alternate language support, or documented reason that the skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic persistence of search history is not necessary to fulfill the core function of searching, filtering, and ranking listings. Unnecessary collection and retention of user activity increases privacy risk and creates a secondary source of sensitive behavioral data without a strong functional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that search history is automatically written to local memory files, but it does not prominently warn users about retention or explain how long the data is kept, who can access it, or how to remove it. This undermines informed consent and can lead to unexpected disclosure of user interests and activity.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs persistent retention of user search activity in local memory files. Search terms, timestamps, result summaries, and item links can reveal user purchasing intent, financial interest, and behavioral patterns, and persistence makes later misuse or unintended access more likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's stated purpose is to search and return Xianyu listings, but it also instructs automatic persistence of search history to local memory files. This creates an unnecessary data-retention surface that can expose user interests, product searches, timing, and links if local memory is later accessed by other skills, users, or operators.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation commands and regex-style patterns are broad enough to trigger on common user shopping requests involving 闲鱼, which can cause the skill to run without sufficiently explicit user intent. In an agent environment, overbroad activation increases the chance of unintended browsing, query execution, or data retrieval actions when the user may only be asking a general question rather than invoking this specific skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest says the skill searches Xianyu and outputs a TOP10 ascending-price list. Lines L212-L224 describe a different operational mode where results are split into multiple messages with timed delivery, which is an extra messaging workflow not reflected in the concise manifest scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.