T01 · Skill Instruction Hijacking
- Location
SKILL.md:53- Finding
Mandatory Recurring Paid-Tier Promotion Alters Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real fundraising-advisor skill, but it overclaims security review, stores sensitive founder data with broad activation and reminder behavior, and includes under-scoped dependencies and network-facing preview content.
Review this carefully before installing. Do not upload confidential BP, cap table, TS, or founder profile data unless you accept local retention in data/users and any host-level memory/reminder behavior. Ask the publisher to remove the unverified ClawHub audit claim, narrow activation triggers, document consent and deletion controls, and pin or remove unused dependencies.
SKILL.md:53Mandatory Recurring Paid-Tier Promotion Alters Agent Responses
scripts/funding_diagnosis.py:393Malformed or Type-Confused JSON Can Crash Scoring or Produce a Misleading Sample Report
requirements.txt:1Unpinned and Unused Third-Party Dependencies Increase Supply-Chain Exposure
preview-page.html:7Bundled Preview Page Makes an Undeclared Request to Google Fonts
声明描述涵盖三项核心能力:融资准备度诊断、TS条款陷阱解析、投资人谈判模拟。代码只支持其中第一项,而且是基于固定阈值与加分规则的8维度评分,不是更广义的融资顾问系统。它读取JSON文件,计算分数、等级、短板和建议,并输出JSON报告;没有处理条款文本、没有法律/融资条款检查、也没有任何对话式谈判模拟。因此描述明显高于代码实际能力,属于实质性能力不匹配。
The changelog adds the chinese tag, which suggests a language or locale targeting choice. In this file there is no accompanying statement that users can choose their language or that the locale restriction is explicitly justified, so this may conflict with the policy against forcing a specific language/locale without opt-in.
The skill claims local-only behavior and references reading user files (for BP analysis, knowledge-base references, and data/users storage), but it does not declare an explicit tool scope such as file read permissions. This creates an authorization/expectation gap: a host may grant broader filesystem access than users expect, or the skill may fail open/behave unpredictably when file access is implicitly available.
Broad top-level triggers like '融资/条款/焦虑' can activate the skill during ordinary conversation, causing unsolicited collection or processing of sensitive business and emotional information. In an assistant environment with multiple skills, ambiguous activation increases prompt-routing confusion and the chance that private content is handled by the wrong skill.
The description explicitly states "中文" as part of the skill positioning, and the comparison table later emphasizes the product language as Chinese. The file does not indicate that users can choose another language or opt into this locale restriction, which can violate language/locale policy expectations for user choice.
Module-level trigger words such as '焦虑', '放弃', or '迷茫' are common everyday terms and may capture unrelated personal or mental-health discussions outside the intended fundraising scope. Because this skill also describes memory, profiling, and follow-up behavior, accidental activation could lead to unnecessary retention or inference about highly sensitive user state.
The document declares lang="zh-CN", which sets the page language and locale to Simplified Chinese for all users. The file does not present this as an optional user choice or document a justified region-specific requirement, which conflicts with the policy against forcing a specific language/locale without opt-in.
The invocation hint 触发:融资/条款/焦虑 includes broad terms such as financing, terms, and especially anxiety, which can overlap with common conversation and make it unclear when the skill should activate. The description does not define specific trigger phrases, scope constraints, or negative examples to prevent unintended invocation.
The page presents contradictory security assertions: the content says the skill was 'Audited by ClawHub' and 'Security scan passed ✓' while the sidebar shows the security audit is still pending. This can mislead users into trusting and installing the skill under false security assurances, which is especially concerning because explicit claims of being verified safe should increase suspicion rather than reduce it.
This markdown file presents all failure-handling instructions and user-facing prompt text exclusively in Chinese, but does not state that the skill is China/Chinese-specific or that the user can opt into this language. That can violate language/locale policy when users are not given a choice or documentation for the constraint.
This markdown file presents all headings, descriptions, examples, and constraints only in Chinese. Under the policy rule for language/locale, forcing a single language without user opt-in or a documented region-specific justification is a natural-language policy violation.
The trigger configuration uses very broad, common phrases such as '不知道', '怎么办', '担心', and '急', which can appear in many ordinary conversations unrelated to fundraising support. In an always-on or loosely scoped skill-routing system, this can cause unintended activation, leading the agent to inject financing advice, emotional coaching, or negotiation scripts into contexts where they were not requested.
The entire system prompt is written to enforce Chinese-only interaction patterns and output structure, but it does not offer users a choice of language or explain a justified locale restriction. This creates a natural-language policy concern because it implicitly forces a specific language without user opt-in.
The routing table uses broad natural-language trigger phrases like '融资', '条款', '焦虑' without clear precedence, disambiguation, or confirmation steps. This can cause the agent to enter the wrong workflow, collect unnecessary sensitive business information, or provide mismatched legal/financial guidance in a high-stakes fundraising context.
The natural-language documentation for the skill is presented only in Chinese, including the usage note and warning. This can violate a language/locale policy when the skill forces a specific language without giving users an explicit choice or documenting a justified locale restriction.
The script's docstring, user instructions, and generated human-readable messages are in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or explanation that the tool is intentionally limited to a Chinese-speaking context.
The description advertises trigger terms including broad everyday words such as “融资/条款/焦虑”, and especially a generic emotional term like “焦虑” can cause accidental activation during normal conversation. In a skill with memory, scheduled tasks, knowledge-base access, and file writing, unintended invocation increases the chance of collecting sensitive business or emotional-state data and taking actions the user did not explicitly intend.
The natural-language description states "🇨🇳 中文" and presents the skill as Chinese-language focused, but does not indicate that users may choose another language or opt in to this constraint. This can violate language/locale policy when a specific language is imposed without explicit user choice or documented regional necessity.
The table identifies the skill language as "中文" while competitor tools are listed with other language options, but there is no accompanying note that users may request another language or that the restriction is justified by a region-specific requirement. This reads as a forced locale constraint in the natural-language documentation.
This markdown file presents all user-facing content exclusively in Chinese, and there is no accompanying note that the skill is region-specific or that users can choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.
This markdown file is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the policy, language constraints should either be optional or clearly justified; no such opt-in or justification appears in this file.
PyYAML is specified with a lower bound only, so builds can resolve to different future versions over time. This weakens supply-chain reproducibility and can unintentionally pull in a vulnerable or breaking release, especially relevant because PyYAML has a history of security advisories.
PyYAML>=5.4.1
edge-tts>=6.0.0
The manifest includes PyYAML without pinning an exact version, while PyYAML has multiple known advisories affecting some releases. Because the resolved installed version is unknown, deployments may consume a vulnerable version, and if the application parses untrusted YAML this could lead to unsafe deserialization or input-validation issues.
edge-tts is also unpinned, which makes installations non-reproducible and increases supply-chain risk if a future release introduces a vulnerability or malicious code. Even without a known current CVE in this finding, allowing arbitrary newer versions is a security hygiene issue.
PyYAML>=5.4.1
edge-tts>=6.0.0
This code opens and parses an arbitrary path provided on the command line, which is a file access operation covered by the missing-warning rule for code files. The script has no confirmation prompt and no explicit warning in comments or docstrings that it will read the specified local file; it only shows generic usage instructions.
No suspicious patterns detected.