Back to skill

Security audit

商品比价

Security checks for vulnerabilities and agentic risk

Overview

This is an incomplete price-comparison skill that requests browser automation and includes anti-bot evasion guidance, so users should review it carefully before installing.

Install only if you are comfortable with a prototype that may automate visits to third-party shopping sites and contains anti-bot evasion guidance. Do not rely on its price or history output as implemented, and avoid using logged-in shopping sessions or sensitive purchasing accounts unless the skill is revised to define consent, rate limits, terms compliance, and report storage behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

该代码的高层主题与声明接近,确实是电商比价方向的自动化脚本框架,没有发现明显额外的越权或无关能力。但声明描述的是一个较完整的比价智能体,而实际代码只是未完成的原型:抓取步骤被注释为 TODO,返回的是固定占位结构;推荐仅基于 finalPrice 排序;没有历史价格、复杂优惠解析或到手价计算。另一个具体偏差是声明点名“淘宝”,代码却实现的是“天猫”。因此描述与实际行为存在实质性不一致,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码与声明存在实质性不匹配。声明强调这是一个可用的“跨平台商品比价智能体”,核心能力是自动抓取多个电商平台的价格并输出完整比价报告。但实际代码中最关键的抓取部分尚未实现,三个主要抓取函数都只是 TODO 并直接返回空结果,因此当前并不能完成声明中的主要任务。代码确实实现了促销解析和到手价计算,这与声明部分一致,但只是支撑能力,不足以证明其具备完整的比价智能体功能。此外,声明提到历史最低价,代码中完全没有相关字段来源、抓取逻辑或计算逻辑。compare_products 也只提供了基础最低价推荐,不等同于声明中的完整结构化报告。综合看,代码更像是一个未完成的价格处理原型,而不是已实现的跨平台商品比价技能。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

该 README 明确列出依赖 automation-browser、web-search-lite 和 file-manager,表明技能会访问电商平台、执行浏览器自动化并管理报告文件。但文档中的“注意事项”仅提到价格时效、反爬和商品匹配,没有对可能的页面访问、登录相关数据处理或本地文件输出给出用户告知。对于 markdown 技能说明,涉及用户数据、隐私或系统完整性的行为应有明确警示。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is written as a Chinese-only skill description and does not indicate that users can choose another language or locale for interaction or output. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown describes automated access to multiple e-commerce platforms and extraction of product and pricing data, but it does not provide an explicit user-facing warning that the skill will perform live browser automation against third-party sites. For markdown files, behaviors that may affect privacy or system integrity should be disclosed clearly; here the operational details are present, but no caution or notice is given to the user.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly recommends anti-bot evasion techniques such as randomized delays, mouse-trajectory simulation, scrolling triggers, and User-Agent rotation. In the context of browser automation against e-commerce platforms, this is dangerous because it facilitates bypassing platform detection and can be repurposed for unauthorized scraping or abuse at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire example file is written in Chinese, including headings, user prompts, and expected outputs, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. Under the policy, a skill that effectively mandates a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire document is written in Chinese and hard-codes Chinese locale assumptions such as converting all prices to人民币(CNY). Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L040-L045 的注释声明该函数会抓取单个平台商品价格并返回商品列表,但 L055-L061 明确保留为 TODO,L065-L075 仅构造固定的示例商品对象。该文档描述与实际行为直接不一致,容易让调用方误以为已执行真实电商抓取。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script explicitly includes '模拟人类行为(反反爬)' logic and comments framing randomized delays as anti-anti-scraping behavior. In a browser automation skill targeting commercial e-commerce platforms, this increases risk because it facilitates evasion of platform access controls or rate-limiting policies, making misuse more likely even though the current implementation is simple.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L089-L094 将 comparePrices 描述为比较多个平台价格并返回比价结果,但其核心依赖的 scrapePlatform 在当前实现中并未抓取真实数据,只返回占位对象。因此 L111-L123 的排序和推荐并不是基于真实平台价格,和注释宣称的能力相矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains user-facing natural-language content such as the module docstring and comments in Chinese only. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function and comments explicitly describe simulating human behavior to evade anti-scraping defenses, which indicates intent to bypass platform protections. Even though the implementation is partial, this creates a capability path for stealthy scraping that can violate site controls, increase abuse risk, and expose the agent operator to legal, compliance, or account-blocking consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The dependency list includes file-manager for report management, implying the skill may create or update comparison report files. The markdown does not warn users that output may be stored or managed as files, which is a user-data-affecting behavior that should be disclosed in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire reference document is written in Chinese and provides no indication that language choice is optional or configurable. Under the policy for natural-language issues, a skill that effectively enforces a specific language without opt-in can be considered a locale/language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.