T01 · Skill Instruction Hijacking
- Location
SKILL.md:91- Finding
Automatic Remote Processing Without Explicit User Confirmation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This AnyShare writing skill is mostly purpose-aligned, but it can upload documents, continue generation after inactivity, and create share links, so users should review it before installing.
Review before installing. Use only with documents you are comfortable uploading to AnyShare, use a least-privilege token, verify generated share links and access controls, and do not allow body generation or sharing to proceed without an explicit fresh confirmation. Avoid confidential materials until the timeout auto-proceed, background job handling, token argument exposure, and temporary-file handling are fixed.
SKILL.md:91Automatic Remote Processing Without Explicit User Confirmation
SKILL.md:141Predictable Shared Temporary Files Store Sensitive Document Content
SKILL.md:685AnyShare Access Token Passed Through Command-Line Arguments
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The documented workflow authorizes automatic progression to full document generation after 5 minutes of silence, without requiring explicit approval for the resulting write/upload actions. Because the skill handles uploaded source material and persists generated outputs, silence being treated as consent can directly cause unauthorized processing of sensitive content.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")
# 上传文件
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @"文件路径" "$URL"
# 确认上传
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo "📄 获取内置写作模板..."
curl -s -X GET \
"https://anyshare.aishu.cn/api/intelli-search/v1/skills/templates/default?skill_name=__全文写作__3" \
-H "authorization: $ACCESS_TOKEN" \
-H "content-type: application/json" > /tmp/template_response.json
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
AUTH=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][2])")
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @/tmp/大纲.md "$URL"
mcporter call anyshare-asmcp.file_osendupload \
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
FULL_GNS=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['docid'])")
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @/tmp/正文.md "$URL"
mcporter call anyshare-asmcp.file_osendupload \
Triggers like 帮我写作 and 基于资料写作 are broad enough to match ordinary writing requests, increasing the chance the skill activates unexpectedly. In this skill's context, activation can lead to file upload, external API calls, document generation, and sharing operations, so overbroad triggering increases the risk of unintended data handling.
The skill defines contradictory approval rules: it says explicit user confirmation is required before generating the body, but also says to auto-proceed after 5 minutes of silence. This ambiguity can cause the agent to perform costly or sensitive actions without valid consent, especially because later steps upload and generate documents from user data.
The workflow explicitly instructs the agent to proceed after a timeout even without explicit approval. That bypasses a normal human-in-the-loop safety boundary and is especially risky here because the downstream actions involve document creation and external service interaction.
Using nohup backgrounds a long-running action so it persists beyond the interactive session. In this skill, that matters because it can continue processing and transmitting user data after the user is no longer actively supervising the workflow.
python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))" > /tmp/selection.txt
nohup bash -c 'mcporter call ... selection:"$(cat /tmp/selection.txt)" skill_name:__大纲写作__1 times:1 --timeout 180000' &
---
The usage flow shows file upload, external processing, persistent storage, and share-link creation, but does not prominently warn users about data transmission and the implications of creating a shareable link. In a document-writing skill, this omission materially increases privacy and confidentiality risk for sensitive project files.
This backgrounded smart_assistant call enables continued body generation outside the normal interaction loop. Combined with the timeout/auto-proceed logic, it reduces user control and can allow unauthorized or unnoticed processing to continue.
SHORT_ID=$(cat /tmp/verify_short_id.txt)
OUTLINE=$(python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))")
nohup mcporter call anyshare-asmcp.smart_assistant \
bot_id:smart_assistant \
query:"基于以下大纲,撰写完整的可行性研究报告正文内容" \
selection:"$OUTLINE" \
This step uploads user-supplied files to an external AnyShare endpoint via curl --data-binary, which is a real external data transmission path. In context, uploading is part of the intended function, but it is still security-relevant because sensitive local content may be transferred off-host and persisted remotely.
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")
# 上传文件
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @"文件路径" "$URL"
# 确认上传
The phase-2 example performs actual external upload of local files to a remote service. Although this is expected functionality, it remains a genuine data-exfiltration surface if the skill is triggered unintentionally or used with confidential documents.
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")
# 上传
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @"$FILE" "$URL"
# 确认
The generated outline is uploaded to the external service, extending the transmission scope beyond source files to derived content that may summarize sensitive materials. This increases exposure because synthesized documents can still contain confidential information.
AUTH=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][2])")
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @/tmp/大纲.md "$URL"
mcporter call anyshare-asmcp.file_osendupload \
The later phase-5 nohup example again detaches sensitive content generation from the user session. In this context, persistence is more dangerous because it processes full outline content and writes results to temporary files and remote storage.
python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))" > /tmp/selection.txt
# 后台执行,避免60秒超时
nohup mcporter call anyshare-asmcp.smart_assistant \
access_token="$ACCESS_TOKEN" \
bot_id:smart_assistant \
query:"基于以下大纲,撰写完整的可行性研究报告正文内容" \
The generated final document is uploaded externally, creating another real transmission point for potentially sensitive content. Because this occurs late in an automated workflow, users may overlook that the full output is being stored remotely.
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
FULL_GNS=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['docid'])")
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
--data-binary @/tmp/正文.md "$URL"
mcporter call anyshare-asmcp.file_osendupload \
The troubleshooting guide instructs users to directly edit a file containing an Authorization token and restart the daemon, but provides no warning about protecting the credential, avoiding accidental disclosure, or using safer secret-handling mechanisms. In an agent-skill context, operational docs are often copied verbatim by users or automation, so normalizing plaintext token handling increases the chance of credential leakage through logs, screenshots, version control, backups, or overbroad file permissions.
该索引在关键词表中将“总结”和“调研”等常见日常词语直接作为模板匹配触发词,且未提供排除条件或更具体的约束。对于基于自然语言描述自动选模板的技能,这类高频通用词容易与普通写作请求混淆,造成意外调用错误模板。
文档说明技能会根据“描述的场景”自动读取对应模板文件,并给出“写个融资用的计划书”这类示例,但没有说明匹配优先级、歧义处理方式或不触发条件。这会让技能在用户未明确指定模板时依据宽泛场景词自行激活,存在误判风险。
The template explicitly guides use of questionnaires, interviews, and focus groups, which commonly involve collection of personal or sensitive information. Because it provides no privacy notice, consent, minimization, retention, or lawful-processing guidance, users may conduct research in a way that violates privacy requirements or exposes respondent data through overcollection or improper handling.
Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection