T01 · Skill Instruction Hijacking
- Location
scripts/valuation.sh:165- Finding
Unconditional Commercial Content Injection into Valuation Reports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent game-account valuation tool, but it asks users to use QR login and sends account-related data over an insecure HTTP service with limited privacy warning.
Review this carefully before installing. Only use it if you are comfortable sending game-account details and QR-login workflow data to the listed third-party valuation service, and avoid using it on untrusted networks unless the endpoint is changed to HTTPS and the QR handling is tightened.
scripts/valuation.sh:165Unconditional Commercial Content Injection into Valuation Reports
scripts/valuation.sh:4Sensitive Authentication and Account Data Transmitted over Plaintext HTTP
scripts/valuation.sh:35Authentication QR Artifacts Stored in a Predictable Shared Temporary Directory
README.md:37Unpinned Installation from Mutable Package and Repository Sources
The README states that account valuation requests are sent to an external http:// service without clearly warning users that account-related information will leave the local environment. Using plain HTTP also exposes those details to interception or tampering in transit, making the privacy and integrity risk materially worse.
The QR-code login and polling flow accesses account-linked data through an external service, but the README provides no warning about the trust boundary, privacy implications, or phishing-like risks inherent in asking users to scan a login QR code. In this skill context, that omission is significant because users may treat the flow as first-party and expose account access or metadata to a remote operator.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README says the skill can be triggered by phrases like 「我的号值多少钱」 and similar examples, which are broad conversational phrases rather than narrowly scoped commands. It does not provide clear constraints or exclusion conditions, so the trigger could match ordinary chat and cause unintended invocation.
The skill invokes shell scripts and even includes an open command, but it declares no tool scope or permissions boundary. That means an agent may gain shell-capable behavior without explicit least-privilege controls, increasing the risk of unintended command execution, external network access, and unsafe side effects if the skill is triggered or modified.
The skill description and user-facing guidance do not clearly warn that some flows require QR-code login and send account-related data to external services. Users may be induced to authenticate or disclose game-account identifiers without informed consent, which raises privacy, account-security, and phishing-style trust risks, especially because the service uses a non-obvious external HTTP endpoint.
The default BASE_URL uses plain HTTP, so account-related identifiers, login UUIDs, polling traffic, and valuation query data are transmitted without transport encryption or server authentication. A network attacker could intercept or modify requests and responses, potentially hijacking sessions, altering QR/login flow behavior, or harvesting sensitive account metadata.
The script exposes helper commands for qrcode, poll, and especially a raw query path that bypass the higher-level workflow described by the skill metadata. In an agent setting, these low-level primitives expand the skill’s effective capability surface and can be abused to send arbitrary request bodies to the backend or automate login-state polling outside the intended single-account valuation flow.
The script stores QR code data and fallback text files in /tmp and opens them automatically, which can expose sensitive login artifacts to other local users or processes on shared systems. Because /tmp is a shared location and the files are named predictably from login_uuid, local disclosure or tampering risk is increased, especially in multi-user or less trusted environments.
No suspicious patterns detected.