T01 · Skill Instruction Hijacking
- Location
SKILL.md:119- Finding
Remote-Controlled Promotional Content Is Relayed Verbatim
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it also gives a remote service control over verbatim user-facing comment content and recommends mutable forced install commands.
Install only if you are comfortable sending Douyin or Xiaohongshu links to the publisher's hosted service. Review any generated comment suggestions carefully, because the skill is instructed to relay backend-provided comment text verbatim. Prefer a pinned, trusted install path over the documented npx clawhub@latest --force commands.
SKILL.md:119Remote-Controlled Promotional Content Is Relayed Verbatim
scripts/update_local_skill.sh:11Mutable Third-Party Installer Is Downloaded and Executed Without Integrity Pinning
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
url = f"{base_url}/health"
req = request.Request(url, headers={"Accept": "application/json"}, method="GET")
try:
with request.urlopen(req, timeout=15) as resp:
payload = json.loads(resp.read().decode("utf-8"))
except error.HTTPError as exc:
body = exc.read().decode("utf-8", errors="replace")
The declared purpose is end-user functionality: transforming social media links into summaries, todo lists, and reminder times. The actual code chunk does none of that. It only checks whether the backend service is reachable and healthy by calling the /health endpoint. While such a script could be a supporting operational component of the overall system, this code chunk's behavior is materially different from the declared skill behavior and introduces an undeclared monitoring capability. Therefore this chunk does not accurately represent the described functionality.
The declared description is about end-user content processing of Douyin/Xiaohongshu links through a hosted service. The actual code does not process links, summarize content, generate todos, or recommend reminder times. Instead, it is an installer/update script for a local skill, invoking external package tooling and making filesystem changes. That is a materially different primary purpose and includes undeclared capabilities related to local installation and deletion.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
The public skill should not redirect normal end users to repository setup or local deployment by default.
The public skill should not implement its own reminder scheduler when OpenClaw cron is available.
## Output Rules
- The default final user-facing result should have these sections:
- `【总结】`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [[ -e "${SKILLS_DIR}/${LEGACY_SLUG}" ]]; then
echo "Removing legacy local directory ${SKILLS_DIR}/${LEGACY_SLUG}"
rm -rf "${SKILLS_DIR:?}/${LEGACY_SLUG}"
fi
echo "Local skill is ready at ${SKILLS_DIR}/${CANONICAL_SLUG}"
The install command uses npx clawhub@latest, which fetches and executes the newest published package at runtime rather than a reviewed, fixed version. If the package is compromised, typosquatted, or a breaking/malicious release is published, users following the documentation could execute untrusted code on their machine.
This command again relies on npx clawhub@latest, causing dynamic execution of whatever version is current at install time. In a skill-distribution context, this increases supply-chain risk because end users are encouraged to run a package-fetching command directly from documentation without version pinning.
The README strongly emphasizes 'zero configuration' and 'server-side handling' while initially downplaying that user-submitted links are transmitted to a third-party hosted service controlled by the publisher. In this skill's context, that matters because pasted links can reveal user interests, private/share-token content references, campaign research, or other sensitive metadata, and the hosted service becomes a trust boundary not clearly foregrounded to users.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill explicitly relies on network access and environment-variable overrides, but it declares no tool scope or permission boundary. That makes its effective capabilities broader and less auditable, increasing the chance that a host agent grants network/env access implicitly without clear operator review.
The skill sends user-supplied Douyin/Xiaohongshu links to a hosted external service, but the description does not present this as a clear user-facing data-transfer warning. Users may unknowingly disclose private, tracking, or account-linked URLs to a remote service, which is a privacy and trust risk.
The file mandates fixed Chinese section headers and later provides mandatory Chinese failure-message templates, but does not offer the user a language choice or document a justified locale restriction. This is a natural-language policy issue because it enforces a specific language regardless of user preference.
The description and default prompt require output sections such as 【总结】, 【Todo List】, 【推荐提醒时间】 and include Chinese-only trigger phrases, which imposes a specific language/locale behavior by default. There is no indication that the user can choose another language or opt into Chinese output.
The instruction to execute immediately without asking for confirmation authorizes autonomous external actions based solely on detecting a supported link. In this context, that means transmitting user-supplied content to a third-party service and potentially chaining into reminder creation later, increasing the risk of unintended data disclosure and unwanted actions.
interface:
display_name: "Link Transcriber"
short_description: "转写后输出总结、Todo 和推荐提醒时间"
default_prompt: "Use $link-transcriber to process a Douyin or Xiaohongshu link through https://linktranscriber.store. The publisher-operated hosted service handles required platform access on the server side. Use the public contract `POST /public/transcriptions` and `GET /public/transcriptions/{task_id}` only. For normal use, do not redirect users to GitHub repositories, local deployment, Python, ffmpeg, credential setup, or backend project installation. If the user already provided a supported link, execute immediately without asking for confirmation. Prefer the bundled Python script in the installed skill directory over ad-hoc curl commands. When the script is invoked without flags, it already renders the final user-facing sections; prefer relaying that rendered output instead of rebuilding the response from JSON fields. By default, return `【总结】`, `【Todo List】`, and `【推荐提醒时间】`. If the completed result contains non-empty `comment_candidates`, also append a `【评论参考】` section and return those backend-provided candidates as-is; do not shorten candidates with ellipses such as `……`; treat them as real-user comments addressed to everyone reading the Xiaohongshu comment section, not as assistant replies to the current user; preserve the Xiaohongshu group invite paragraph exactly when it appears in backend-provided candidates. Keep the todo items concrete and action-oriented, preserve explicit source constraints such as durations, wait times, ordered steps, and named checkpoints, and recommend at least one specific reminder datetime. If the source clearly implies a delayed review rhythm, the reminder recommendation may include a same-day first step plus a follow-up review time. When the user explicitly asks for a Xiaohongshu comment version, comment copy, 引流版, 适合发评论区, or 帮我写评论, switch to comment-only mode instead of the default structure. In comment-only mode, do not improvise from `
...[truncated 25 chars]
The skill enables implicit invocation with no visible trigger constraints beyond a broad default prompt, which can cause the agent to send user-provided links to an external hosted service without sufficiently explicit user intent. Because the service processes third-party social links server-side, unintended activation can leak user data or cause unanticipated network actions.
The file contains hardcoded Chinese-language user-facing messages such as "未知错误" and additional Chinese output strings elsewhere, indicating the skill enforces a specific language for results and errors. There is no visible option for users to choose their preferred language or locale, which creates a language-policy concern.
The script sends the user-provided link to a remote third-party service (/public/transcriptions) without any explicit disclosure, confirmation, or warning at the point of use. Because Douyin/Xiaohongshu links can embed personal, private, or account-associated content, silent transmission can cause privacy and data-handling risks, especially since the skill’s core function depends on server-side access outside the user’s local environment.
The script executes npx clawhub@latest, which fetches and runs the newest published package version at install time rather than a reviewed, pinned release. This creates a supply-chain risk: if the package is compromised, unpublished/replaced, or a breaking/malicious update is released, anyone running the updater will execute attacker-controlled code locally.
Natural-language instructions, examples, and operational guidance are written exclusively in Chinese, and the file does not indicate that the skill is region-specific or that users may choose another language. Under the language/locale policy, forcing a single language without opt-in can be a policy concern unless the restriction is explicitly justified.
This markdown file contains user-facing instructions exclusively in Chinese, which can constitute a language/locale policy violation when no opt-in or alternative language is provided. The file does not indicate that the skill is intentionally region-specific or that users may choose another language.
The deployment guide discloses developer-local filesystem paths unrelated to safe public deployment of the skill. While the paths do not by themselves grant access, they leak internal usernames, directory structure, project names, and likely repository layout, which can aid targeted phishing, social engineering, or follow-on attacks against the maintainer environment.
No suspicious patterns detected.