Back to skill

Security audit

阿里商品月销查询

Security checks for vulnerabilities and agentic risk

Overview

This skill does the stated job of looking up Taobao/Tmall monthly sales through a disclosed EarlyData API and does not show hidden persistence, credential theft, destructive behavior, or unrelated access.

Before installing, understand that product IDs you ask about will be sent to EarlyData to retrieve sales data. The skill is mainly documented and surfaced in Chinese, so non-Chinese users may see Chinese status and error messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

All user-facing strings, comments, and function documentation are in Chinese, and the skill returns Chinese-only status and error messages. The policy allows language constraints when users are offered a choice or when the locale restriction is clearly documented and justified, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/agent.py (reported line 19)May include surrounding context.

python
for package in required_packages:
        try:
            __import__(package)
        except ImportError:
            missing_packages.append(package)

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'When to use' section provides a few positive examples, including a broad phrase like '帮我看看这个天猫商品卖了多少', but does not specify exclusion conditions or a precise trigger scope. This can cause unintended invocation when users casually discuss product sales without clearly requesting this specific API-backed lookup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function sends a user-supplied product identifier, derived from a product URL or raw item ID, to a third-party service (mi.earlydata.com) without any visible disclosure, consent, or privacy notice in the skill logic. While the data is not highly sensitive by itself, this still exposes user-provided input and usage patterns to an external party and may violate user expectations or platform data-handling requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.