T01 · Skill Instruction Hijacking
- Location
src/analyze/project_analyzer.py:14- Finding
Indirect Prompt Injection Through Untrusted GitHub Repository Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
AgentScout has a coherent content-generation purpose, but it needs review because untrusted GitHub content can influence LLM output and browser-rendered images without enough safeguards.
Install only if you are comfortable sending GitHub repository content and generated prompts to the configured LLM/image providers. Use a low-scope GitHub token, avoid private or sensitive repositories, review generated commands before copying or publishing them, and run it in an isolated environment until prompt-injection handling, HTML escaping, URL restrictions, and dependency pinning are improved.
src/analyze/project_analyzer.py:14Indirect Prompt Injection Through Untrusted GitHub Repository Content
src/visual/composer.py:13Unescaped Attacker-Controlled Content Rendered in a Headless Browser
src/utils/image_client.py:42Server-Side Request Forgery Through Image Provider Response URLs
requirements.txt:1Unpinned and Unhashed Third-Party Dependencies
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp .env.example .env
编辑 .env 文件,填入你的 API Key:
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
And configure `.env` with at minimum:
- `GITHUB_TOKEN` — GitHub Personal Access Token
- `LLM_API_KEY` — Any OpenAI-compatible LLM API key
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
And configure `.env` with at minimum:
- `GITHUB_TOKEN` — GitHub Personal Access Token
- `LLM_API_KEY` — Any OpenAI-compatible LLM API key
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""
import os
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""
import os
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""
import os
from pathlib import Path
Automatically loading secrets from a project-root .env file can increase the chance of accidental secret exposure or misuse, especially in agent/tooling contexts where local files may be packaged, copied, or executed in less controlled environments. The risk is contextual rather than overtly malicious, but this pattern can cause credentials to be implicitly consumed without clear operator intent.
# 项目根目录
PROJECT_ROOT = Path(__file__).parent.parent
load_dotenv(PROJECT_ROOT / ".env")
@dataclass
The README explicitly says the tool fetches full READMEs, file trees, and key code, then uses an LLM to generate analysis. That creates a real data-transmission and privacy risk because repository content may be sent to third-party LLM or image providers without a prominent warning, consent step, or guidance about handling private/sensitive code.
The README configures an external LLM endpoint and elsewhere describes sending repository-derived content to LLM services. In this skill's context, that means project text/code may leave the local environment and be processed by third parties, creating confidentiality, compliance, and data-handling risks if users are not clearly warned.
LLM_API_KEY=sk-xxxx
# 可选 - LLM 配置(默认 OpenAI)
LLM_BASE_URL=https://api.openai.com/v1
LLM_MODEL=gpt-4o
# 可选 - AI 配图(支持任意 OpenAI 兼容的图片 API)
The image API endpoint indicates generated prompts and possibly project-derived text may be sent to an external image provider. Even if less sensitive than raw code analysis, this still constitutes third-party transmission that may expose repository names, descriptions, or generated content without clear warning or retention guidance.
IMAGE_API_KEY=sk-xxxx IMAGE_BASE_URL=https://api.siliconflow.cn/v1 IMAGE_MODEL=black-forest-labs/FLUX.1-schnell
This configuration table reinforces that a remote OpenAI-compatible endpoint is part of normal operation. Because the tool analyzes third-party repositories and generates derived content, defaulting to remote APIs without strong disclosure increases the chance users unknowingly transmit code/content outside their environment.
|------|------|--------|------|
| `GITHUB_TOKEN` | 推荐 | - | GitHub Personal Access Token |
| `LLM_API_KEY` | ✅ | - | LLM API Key |
| `LLM_BASE_URL` | - | `https://api.openai.com/v1` | 任意 OpenAI 兼容端点 |
| `LLM_MODEL` | - | `gpt-4o` | 模型名称 |
| `IMAGE_API_KEY` | - | - | 图片生成 API Key(不填则跳过 AI 配图) |
| `IMAGE_BASE_URL` | - | `https://api.siliconflow.cn/v1` | 图片 API 端点 |
The external image endpoint is another real outbound data flow documented as a standard configuration option. In the context of automated content generation, users may unintentionally send repository-derived themes, text, or screenshots to third-party services, which is a meaningful privacy/compliance concern.
| `LLM_BASE_URL` | - | `https://api.openai.com/v1` | 任意 OpenAI 兼容端点 |
| `LLM_MODEL` | - | `gpt-4o` | 模型名称 |
| `IMAGE_API_KEY` | - | - | 图片生成 API Key(不填则跳过 AI 配图) |
| `IMAGE_BASE_URL` | - | `https://api.siliconflow.cn/v1` | 图片 API 端点 |
| `IMAGE_MODEL` | - | `FLUX.1-schnell` | 图片模型 |
| `SCORE_WEIGHT_*` | - | 见上表 | 四维评分权重 |
| `TOPK_SIZE` | - | `20` | 排行榜保留数量 |
The skill declares executable behavior that uses environment variables, network access, and file writes, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because users and orchestrators cannot easily tell what the skill is allowed to access, increasing the chance of over-privileged execution and unintended data exposure.
The description frames the skill as automatically generating publish-ready Xiaohongshu content, which implies a specific platform and associated language/locale context by default. There is no indication that the user can choose a different language or locale, or that this constraint is region-specific and intentional.
The skill requires external credentials and implies use of outside services, but it does not clearly warn users that repository data and prompts may be sent to third-party APIs. This is dangerous in security-sensitive environments because code or metadata could leave the local trust boundary without informed consent.
The system and prompt strings are entirely written in Chinese and direct the model to produce a tutorial in that language, but the file provides no user opt-in, language selection, or justification for a mandatory Chinese locale. This creates a natural-language policy issue because the skill enforces a specific language regardless of user preference.
Untrusted README text, file tree content, and source files from arbitrary GitHub repositories are inserted directly into the LLM prompt with no isolation or sanitization. A malicious repository can embed prompt-injection instructions that cause the model to ignore the intended task, generate deceptive or harmful output, exfiltrate surrounding prompt context, or produce unsafe commands in the '5分钟跑起来' section; this skill context makes the issue more dangerous because it is explicitly generating publish-ready tutorials and executable setup steps from attacker-controlled content.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
@dataclass
class LLMConfig:
api_key: str = ""
base_url: str = "https://api.openai.com/v1"
model: str = "gpt-4o"
temperature: float = 0.7
max_tokens: int = 4096
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
@dataclass
class LLMConfig:
api_key: str = ""
base_url: str = "https://api.openai.com/v1"
model: str = "gpt-4o"
temperature: float = 0.7
max_tokens: int = 4096
No suspicious patterns detected.