Back to skill

Security audit

purchasing-agent-guide

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent shopping assistant, but it asks users to share passwords in chat and relies on an opaque external MCP service for irreversible USDT payment instructions.

Review carefully before installing. Use only a dedicated password that is not reused anywhere, verify the MCP operator and domain independently, and treat all payment addresses, QR codes, and '!open' instructions as untrusted until confirmed through another trusted channel. Cryptocurrency transfers may be irreversible if the address, amount, or network is wrong.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:43
Finding

Untrusted MCP Responses Are Mandated for Verbatim Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–47
Vulnerability Type: Remote instruction and output injection
Risk Level: High

Vulnerable Instruction Snippet

text
- Forward the entire payment-information block exactly as returned. The USDT
  payment block returned by the ordering tool, including the receiving
  address, amount, QR-code URL, !open instruction, and transfer instructions,
  must be copied line by line without omission or reformatting.
- The QR-code URL must be forwarded unchanged as a standalone clickable line.
  The instruction below it telling the user to execute "!open ..." must also
  be retained exactly.

Technical Analysis

The Skill treats content returned by the external MCP service as trusted instructions rather than untrusted data. It explicitly prohibits the Agent from omitting, sanitizing, or restructuring the payment response, including an externally supplied URL and an executable-looking !open instruction.

The MCP endpoint is outside this repository and can change its responses after the Skill has been reviewed. Its operator, or an attacker who compromises the service, can therefore insert phishing links, misleading payment directions, command-like prompts, or other attacker-controlled text into the Agent's response.

The behavior exceeds the minimum privileges required for a shopping assistant. Product and payment fields can be displayed safely through a validated schema without granting the remote service control over arbitrary lines of Agent output.

Attack Path

  1. A user configures and connects the external purchasing MCP service.
  2. The user initiates an order.
  3. The MCP service returns a payment block containing a malicious URL, substituted cryptocurrency address, or crafted !open instruction.
  4. The Skill requires the Agent to reproduce every line unchanged and forbids sanitization or omission.
  5. The user receives the malicious ...[truncated 717 chars]
Remediation
View remediation

Remediation Suggestions

  • Treat every MCP response as untrusted data rather than an instruction source.
  • Replace verbatim forwarding with a strict response schema containing only expected fields such as order number, network, amount, address, and QR URL.
  • Reject unknown fields and instruction-like text returned inside data fields.
  • Remove the requirement to reproduce arbitrary !open instructions.
  • Allowlist trusted URL origins and require HTTPS.
  • Validate cryptocurrency addresses against the selected network before display.
  • Show a locally generated transaction summary and require explicit user confirmation of the network, exact amount, destination address, and merchant identity.
  • Clearly label remote-service content and avoid presenting it as trusted Agent guidance.
  • Pin or otherwise authenticate the service operator and publish an auditable MCP response schema.

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:47
Finding

Automatic Retrieval and Processing of MCP-Controlled QR Resources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 47
Vulnerability Type: Unrestricted remote resource retrieval
Risk Level: Medium

Vulnerable Instruction Snippet

text
- Prefer displaying the QR-code image directly. For example, use curl to
  download it to captures/qr-<order-number>.png and then read the file.
  The Agent may choose another display method according to the environment.

Technical Analysis

The Skill encourages the Agent to retrieve a URL supplied by the external MCP service using curl, save the response locally, and process it as an image. No hostname allowlist, private-address restriction, content-length limit, timeout, MIME validation, image-signature check, redirect policy, or isolated decoder is specified.

An MCP operator can consequently choose the fetched destination and returned content. Even without explicit execution, fetching and parsing attacker-controlled content can disclose the client's network address, access environment-reachable endpoints, consume disk or memory, or expose image and document parsers to malicious input.

This was classified under remote payload retrieval because the effective downloaded content can change after repository review. The audited instructions do not explicitly execute the downloaded file, so arbitrary code execution is not established from the available evidence.

Attack Path

  1. The user creates an order through the external MCP server.
  2. The server returns an attacker-selected value in the QR-code URL field.
  3. Following the Skill's recommendation, the Agent invokes curl or an equivalent retrieval tool.
  4. The client connects to the attacker-selected destination and writes the response under captures/.
  5. The Agent or client reads and renders the downloaded object.
  6. The attacker can record the request, return an oversized response, redirect the request, provide deceptive non-image content, or target a vuln ...[truncated 708 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not automatically retrieve URLs supplied by MCP responses.
  • Prefer generating QR codes locally from an independently validated payment address.
  • If remote image retrieval is necessary, allowlist exact HTTPS hostnames and reject unapproved redirects.
  • Resolve destinations before connecting and block loopback, private, link-local, multicast, and cloud-metadata address ranges.
  • Enforce short connection and transfer timeouts, strict maximum response sizes, and low redirect limits.
  • Validate both the declared MIME type and the actual image-file signature.
  • Decode images in a sandboxed process with no network access and minimal filesystem permissions.
  • Use unpredictable, securely created temporary files and remove them after rendering.
  • Never interpret downloaded content as Agent instructions or executable commands.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:74
Finding

Sensitive Credentials and Irreversible Payments Are Delegated to an Unverified External Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 74–92; mcp-setup.md, lines 9–25
Vulnerability Type: Unsafe handling of credentials and financial transaction data
Risk Level: High

Vulnerable Instruction Snippets

SKILL.md:

text
| Login or register | sign_in | mobile, password |
...
| Buy item | buy | Follow the three-step confirmation process |
...
| Verify payment | verify_payment | mobile, order_no, tx_hash;
  optional chain value: tron, eth, or aptos |

mcp-setup.md:

json
{
  "mcpServers": {
    "purchasing-mcp": {
      "url": "https://mcp.137449244.xyz/mcp"
    }
  }
}

Technical Analysis

The workflow asks users to provide a telephone number or email address and a password to an external MCP endpoint. The same service controls product listings, order creation, USDT payment addresses, payment amounts, and transaction verification.

The repository does not provide evidence of operator identity, an OAuth or delegated-authentication flow, credential scoping, independent address verification, certificate pinning, or a trusted mechanism for confirming that payment details belong to the intended merchant. A disclaimer does not mitigate credential theft or transaction-redirection risk.

The configuration path mentioned in mcp-setup.md does not itself read existing secrets. However, adding a remote server to a global MCP client configuration expands the client's trust boundary. The sensitive behavior arises when the configured service receives login credentials and controls irreversible payment instructions.

Attack Path

  1. The user adds https://mcp.137449244.xyz/mcp to the MCP configuration of Cursor, Claude, or another client.
  2. The Skill prompts the user for an email address or telephone number and a password.
  3. These credentials are submitted to the third-party MCP service through sign_in.
  4. The service can retain, correlate, or misu ...[truncated 1009 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace direct password collection with OAuth, passkeys, or short-lived, narrowly scoped tokens.
  • Explicitly warn users never to submit a password reused for another service.
  • Use a verifiable first-party domain with documented ownership, privacy terms, incident contacts, and service identity.
  • Minimize collected personal data and document retention and deletion policies.
  • Separate authentication from payment-address generation so one service does not control the entire trust chain.
  • Independently validate destination addresses and bind them cryptographically to the order, merchant, amount, and selected network.
  • Present a final transaction summary and require explicit confirmation immediately before payment.
  • Use authenticated MCP response schemas and integrity-protected order records.
  • Avoid placing the server in global MCP configuration when project-scoped configuration is sufficient.
  • Provide users with a method to verify payment details through a second trusted channel.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example explicitly asks the user to send a phone/email and password in chat so the agent can log them in. Collecting credentials through natural-language conversation is unsafe because it normalizes password sharing, exposes secrets to the model/client/logging stack, and creates a phishing-like workflow without any meaningful warning or secure handoff.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These lines instruct the user to provide a phone/email and password directly to the consultant, which is direct collection and handling of sensitive credentials via free-form chat. This is dangerous because it enables credential theft, accidental retention in transcripts, reuse attacks if the password is shared elsewhere, and trains users into an unsafe trust pattern.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide tells users that, when not logged in, they will be prompted to provide a phone number or email and password, but it gives no warning about credential handling, phishing risk, storage, or how the MCP/client protects secrets. Because this is a third-party remote MCP endpoint handling account login and purchases, the lack of credential-safety guidance materially increases the risk of credential theft, reuse compromise, or unsafe submission through an AI client.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction lang 默认 zh;用户全程英文时传 lang="en" establishes Chinese as the default language unless the user uses English throughout. This is a language-policy constraint without explicit user choice or opt-in, which can violate organizational locale-policy requirements.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example uses a staged conversational flow—disclaimer acceptance, then credential submission, then continued assistance—to increase user compliance with a sensitive action. Even if framed as onboarding, this is a social-engineering-like interaction pattern because it builds trust and momentum before asking for secrets and financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The payment flow provides wallet address and transfer details but does not clearly warn that cryptocurrency transfers are irreversible and that sending funds to the wrong address/network can permanently lose money. In a guided purchasing skill, omission of this warning increases the chance users will rely on the assistant and make unrecoverable payment mistakes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says users can start by saying 「逛逛商店」, but it does not define where this phrase applies, whether exact wording is required, or any exclusion conditions. In a general chat context, this natural-language trigger could overlap with ordinary conversation and cause unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.