T01 · Skill Instruction Hijacking
- Location
SKILL.md:92- Finding
Skill instructions attempt to override outer agent response rules
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This procurement API skill is mostly coherent, but it includes broad file/URL image handling and silent usage reporting that users should review before installing.
Review this skill before installing. It needs API credentials and sends procurement text, questions, session metadata, and optional images to 1688 services. Only pass image paths you intentionally want uploaded, avoid remote image URLs unless you trust the target, and be aware that each successful command also reports usage metadata without a documented opt-out.
SKILL.md:92Skill instructions attempt to override outer agent response rules
SKILL.md:31User-controlled values are interpolated into documented shell commands
scripts/_img_upload.py:113Unrestricted local paths can be read and uploaded as images
scripts/_img_upload.py:31Remote image retrieval permits SSRF and unbounded downloads
scripts/_tracker.py:17Every successful command performs undisclosed authenticated telemetry
requirements.txt:1Dependency version is not reproducibly pinned
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The reported return shape and behavior differ from the mandated raw JSON passthrough and file/stream mode, meaning the skill may inject parsed summaries or additional fields into the model context instead of safely streaming results. This can expose more data to the model than intended and violates the documented containment mechanism for potentially large or sensitive instance data.
The skill metadata says it supports only two procurement API operations, but this helper silently adds arbitrary remote URL fetching before upload. That expands the trust boundary and can be abused as an SSRF primitive to make server-side requests to attacker-controlled or internal endpoints, potentially exposing internal services, credentials, or enabling pivoting through the agent environment.
The skill declares no explicit tool/permission scope even though its documented behavior requires filesystem access, network access, and environment-dependent execution. Missing scope boundaries increases the blast radius if the skill is invoked in an unintended context or later extended, because reviewers and policy engines cannot constrain its actual capabilities.
The skill description is written as a Chinese-only operating specification for the skill, and it does not indicate that users may choose another language or locale. This can amount to a language/locale policy violation if the organization requires user opt-in before constraining language.
The CLI performs an additional telemetry/reporting action via _tracker.report_skill_usage() that is unrelated to the core procurement function and is not disclosed in the file's user-facing output. Silent outbound reporting can leak usage metadata or environment details and creates an unexpected side effect in a tool that otherwise appears to be a direct API wrapper.
The usage-tracking call is executed silently and there is no user-facing disclosure in this file that the CLI may report execution data. In a cloud API skill, undisclosed reporting is more concerning because it may expose invocation patterns, identifiers, or operational metadata beyond the expected procurement workflow.
The authentication helper falls back to reading API credentials from a local config file when the environment variable is absent. That broadens the trust boundary and allows the skill to consume secrets from local host state outside its declared cloud-API invocation path, increasing the chance of unintended secret use, cross-skill credential exposure, or abuse if the config file is readable or tampered with.
This module reads an API credential from both a local config file and the ALI_1688_AK environment variable, which is a sensitive-secret access path. While the code has internal docstrings, it provides no user-facing warning, confirmation, or visible logging that credentials will be read from the environment or fallback config, so the behavior is not disclosed within this file.
This code's natural-language documentation and user-facing exception messages are exclusively in Chinese, including the stated output shape containing markdown text. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a language/locale policy violation.
The docstring states this module uploads local images as base64, but the implementation also downloads arbitrary remote images first. This mismatch hides network-fetch behavior from reviewers and operators, increasing the chance that dangerous SSRF-like capability is overlooked and deployed without appropriate controls.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
suffix = _image_suffix_from_response(clean_url, resp)
local_path = os.path.join(output_dir, "remote_image_{}{}".format(index, suffix))
total_bytes = 0
with open(local_path, "wb") as f:
for chunk in resp.iter_content(chunk_size=DOWNLOAD_CHUNK_SIZE):
if not chunk:
continue
This Python file contains natural-language documentation and output strings entirely in Chinese, including the standardized output description and later user-facing error/help text. Because the skill appears to standardize output for all commands and does not offer opt-in language selection or document a region-specific justification, it risks violating language/locale policy.
This code introduces an undisclosed outbound network call for telemetry on every CLI execution, which exceeds the skill's stated two API functions and creates a data-flow path not described in the manifest. Even though the payload is limited to skill name, version, scene, and channel, hidden network behavior undermines transparency, can violate user expectations or policy constraints, and could be repurposed later for broader exfiltration via the shared HTTP helper.
Telemetry is sent on every invocation without any notice or consent mechanism in this file, creating covert outbound communication from the user's environment. Silent exception handling further reduces visibility, making the behavior harder to detect or audit and increasing privacy and compliance risk even if the current payload appears minimal.
The CLI explicitly allows query results to be emitted to stdout via --output-mode stdout, which directly contradicts the skill's documented safety requirement that instance query data must use file/streamed output to avoid entering the model context. In an agent setting, stdout is commonly captured and fed back into the LLM, so this creates a straightforward data-exfiltration path for potentially large or sensitive API results.
The help text advertises that query results may be returned as direct stdout JSON, normalizing an unsafe usage pattern that bypasses the skill's stated file-mode-only boundary. Because operators and calling agents rely on CLI help for correct invocation, this documentation inconsistency materially increases the chance that sensitive instance data will be routed into model-visible output.
The skill sends user-provided requirement, questions, session ID, and possibly uploaded image-derived URLs to external services via api_post, but this file contains no confirmation prompt, logging, or user-facing notice about that transmission. Because the operation sends user data over the network and the function immediately starts the inquiry flow, it meets the missing-warning criterion for code files.
The code exposes additional capability beyond the stated skill scope by accepting both local image paths and remote image URLs, then turning them into uploaded image payloads. This scope drift is security-relevant because hidden or undocumented inputs expand the attack surface, can surprise users, and may enable unintended data transfer through a skill described as cloud-API-only and limited to inquiry start/query flows.
The function reads caller-supplied local file paths and uploads them, and also fetches/uploads externally referenced image URLs. In an agent environment, this can lead to exfiltration of local files or transmission of sensitive image content to remote services, which is especially risky because the skill description says it is cloud-API-only and does not advertise local file handling.
The code uploads local images and remote-image-derived content to external services without any visible confirmation, provenance checks, or safeguards in this path. Because the inputs may reference sensitive local files or private business images, silent transmission creates a material risk of unintended data exfiltration.
No suspicious patterns detected.