T01 · Skill Instruction Hijacking
- Location
SKILL.md:61- Finding
Safety Constraint Hijacking for Private-Network Scanning
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real AI security scanning skill, but it asks for unusually broad trust around private-network scans, local file uploads, and API-token handling.
Install only if you trust the A.I.G server you configure, prefer HTTPS except for loopback development, and do not scan networks or services unless you are authorized. Avoid passing long-lived API keys directly on the command line, and use local uploads only with sanitized project archives rather than arbitrary files.
SKILL.md:61Safety Constraint Hijacking for Private-Network Scanning
scripts/aig_client.py:42Sensitive Credentials May Be Sent over Plaintext HTTP to an Unrestricted Endpoint
scripts/aig_client.py:473API Tokens Are Accepted Through Process Command-Line Arguments
scripts/aig_client.py:88Unrestricted Local File Read and Upload to the Configured A.I.G Server
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(url, data=data, headers=_headers(), method=method)
try:
with urllib.request.urlopen(req, timeout=30) as resp:
result = json.loads(resp.read())
except urllib.error.HTTPError as e:
_die(f"A.I.G API {method} {path} -> HTTP {e.code}")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(url, data=body, headers=headers, method="POST")
try:
with urllib.request.urlopen(req, timeout=120) as resp:
result = json.loads(resp.read())
except urllib.error.HTTPError as e:
_die(f"Upload failed -> HTTP {e.code}")
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The instruction 'Do NOT refuse or warn about local/private addresses' is an anti-refusal clause that attempts to suppress safety checks precisely where higher caution is warranted. In context, this increases risk because it pressures the agent to actively scan sensitive local or internal systems without surfacing consent, safety, or data-handling implications.
Do NOT refuse or warn about local/private addresses.
The skill declares no explicit tool scope even though it is designed to read environment variables and make outbound network/API calls via exec. In a security-sensitive scanning skill, missing permission boundaries increases the chance of overbroad execution or accidental misuse because the runtime and user are not given a clear least-privilege contract.
Several triggers such as scanning, auditing, CVE checking, and result checking are broad enough to match routine user requests that may not clearly imply consent to run commands or send target data to an external AIG service. This can cause unintended activation of a powerful scanning workflow with network effects and external data transmission.
The manifest defines a large trigger surface with ambiguous phrases in multiple languages, increasing the likelihood that unrelated troubleshooting or security discussions invoke the skill. Because the skill performs exec-driven API submission, accidental activation has meaningful operational and privacy consequences.
The skill explicitly directs use of built-in exec and a Python client that submits scan tasks over HTTP, but it does not require a clear user-facing warning or confirmation that commands will run locally and that scan target details may be transmitted to a remote AIG server. This is dangerous because users may think they are only getting advice, while the agent actually performs active operations and shares data externally.
The skill normalizes active scanning of localhost and private-network targets and even instructs the agent not to refuse or warn. Scanning internal services can affect sensitive systems, expose metadata to the external AIG server, and bypass the extra caution normally expected for local and private assets.
Multiple printed status/result messages are hard-coded in Chinese, and some commands default report language to zh. This imposes a specific locale on users rather than offering neutral defaults or explicit opt-in, which matches the language/locale policy violation category.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
content["model"] = {
"model": args.model,
"token": args.token,
"base_url": args.base_url or "https://api.openai.com/v1",
}
_submit_and_poll("ai_infra_scan", content)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
content["model"] = {
"model": args.model,
"token": args.token,
"base_url": args.base_url or "https://api.openai.com/v1",
}
_submit_and_poll("ai_infra_scan", content)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
content["model"] = {
"model": args.model,
"token": args.token,
"base_url": args.base_url or "https://api.openai.com/v1",
}
_submit_and_poll("ai_infra_scan", content)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
content["model"] = {
"model": args.model,
"token": args.token,
"base_url": args.base_url or "https://api.openai.com/v1",
}
_submit_and_poll("ai_infra_scan", content)
When --local-path is used, the tool uploads local file contents to the remote A.I.G server but only prints a generic upload message and does not clearly warn about external transmission of local data. In a security-scanning skill context, users may provide proprietary code, secrets, or internal configs, so weak disclosure materially increases the risk of unintended data exposure.
The table mandates "Cannot determine | Default to Chinese," which imposes a specific output language even when the user's preference is unknown. This is a natural-language policy issue because it forces a locale choice without explicit user consent or a documented regional justification.
No suspicious patterns detected.