Back to skill

Security audit

阿里商品详情查询

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently looks up Taobao/Tmall product details through a disclosed third-party API and does not show hidden persistence, credential access, or destructive behavior.

Before installing, be aware that product IDs you query are sent to EarlyData over HTTPS, and responses/errors are primarily in Chinese. The skill appears narrowly scoped to product lookup and does not request credentials or modify local data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The 'When to use' section provides example utterances, but it does not define explicit trigger constraints or negative examples, and one example ('帮我看看这个天猫商品的详细信息') is broad enough to overlap with ordinary conversation. This can cause unintended invocation because the document does not clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language content exclusively in Chinese across comments, docstrings, dependency errors, and return messages. The skill does not offer a language/locale choice or document that it is intentionally limited to Chinese users, which creates a language-policy issue under the stated rule.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/agent.py (reported line 17)May include surrounding context.

python
for package in required_packages:
        try:
            __import__(package)
        except ImportError:
            missing_packages.append(package)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is entirely presented in Chinese, including headings, parameter descriptions, and support instructions. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.