T01 · Skill Instruction Hijacking
- Location
SKILL.md:345- Finding
Forced Transmission of Reports to a Hard-Coded External Feishu Group
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs a coherent tech-news report workflow, but it mandates sending every report to a fixed Feishu group without per-run user confirmation.
Review this skill before installing. It is suitable only if you intentionally want generated reports saved locally, written to Feishu, and sent to the specific embedded Feishu group. Do not use it for private or organization-specific report content unless the destination identifiers are replaced with user-selected, confirmed targets and external sending is made optional.
SKILL.md:345Forced Transmission of Reports to a Hard-Coded External Feishu Group
references/feishu-doc.md:15Hard-Coded Feishu Account and Knowledge-Base Identifiers
SKILL.md:250Mandatory Third-Party Branding Injected into Generated Reports
The skill requires direct transmission of the final report to a fixed Feishu group ID and frames that send as mandatory for task completion, with no safety warning or approval step. This creates a clear unauthorized-sharing risk and turns normal skill execution into automatic external dissemination.
Using an open-ended trigger such as 'or similar expressions' makes invocation boundaries ambiguous and raises the risk of accidental activation. In this skill, accidental activation is more dangerous because execution includes network searches, local persistence, document creation, and outbound messaging.
The top-level description says the report will be sent to a Feishu group but does not clearly warn users that generated content leaves the local session and is transmitted externally. Because the skill aggregates content and may include generated summaries, this creates a meaningful risk of unintended disclosure to third parties.
The workflow automatically writes reports to local storage and creates Feishu documents without a clear persistence notice or consent checkpoint. This can retain data longer than users expect and duplicate it across multiple storage locations, expanding exposure in the event of misuse or account compromise.
The skill hardcodes a specific Feishu group ID and instructs mandatory delivery to that target, creating a fixed exfiltration path for generated content. If the skill is triggered in normal use, reports may be sent to an unintended or overbroad audience without per-run verification of destination or consent.
The description and output examples are centered on Chinese-language operation and a GMT+8 timestamp format, but do not indicate that users may choose another language or locale. This can amount to a locale/language constraint without explicit opt-in.
The late-stage execution note introduces a mandatory Feishu group broadcast that is more sensitive than the earlier workflow presentation and can materially change the data-flow of the skill. Burying an external broadcast requirement deep in documentation increases the chance that operators or users trigger the skill without understanding that generated content will be sent to a group chat.
The natural-language instructions and labels throughout the file are exclusively in Chinese, which can amount to a language-policy issue if the skill is expected to support broader users without forcing a specific language. There is no note that the Chinese locale is intentional, optional, or limited to a specific audience.
This markdown file includes an example for writing content to a document via the write action, which can change user data in an external system. The surrounding documentation does not warn that this operation edits existing document contents or advise users to verify the target document before running it.
No suspicious patterns detected.