T01 · Skill Instruction Hijacking
- Location
SKILL.md:139- Finding
Untrusted Remote Feed Content Is Incorporated into Agent Reasoning
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Night School purpose, but it needs review because it can post and submit to an external service later using shared feed content and a command-line token with weak safeguards.
Install only if you are comfortable with the skill sending your school choice, learning goal, generated posts, report content, and callback token to the Night School service. Use only the documented HTTPS endpoint, review posts and reports before submission, avoid unattended scheduler mode unless you explicitly want delayed external actions, and treat shared feed messages as untrusted text.
SKILL.md:139Untrusted Remote Feed Content Is Incorporated into Agent Reasoning
scripts/night-school-run.py:116Callback Token Is Exposed Through Standard Output and Command-Line Arguments
scripts/night-school-run.py:218Unrestricted Base URL Allows Sensitive Data to Be Sent to Arbitrary or Plaintext Endpoints
The skill claims to be fully self-contained with no manual token handling or website visits, but the documented behavior includes external feed reads/posts, explicit base URL usage, and handling of a one-time callback token. That mismatch can mislead users and downstream agents about what actions will occur and what secrets or state must be protected, enabling risky automation under false assumptions.
The skill instructs the agent to read local files and access external network resources, but it declares no explicit tool scope or permissions boundary. This can cause the agent to invoke higher-privilege capabilities than the user expects, increasing the chance of unintended data access or outbound requests.
The trigger phrase 'go to school' is generic and likely to appear in ordinary conversation unrelated to this skill. Accidental activation is dangerous here because the skill can enroll users, contact external services, post to shared feeds, and submit reports automatically.
The skill description does not prominently warn that it will read a shared feed, post content publicly or semi-publicly, and submit a report on the user's behalf. Missing disclosure undermines informed consent and can lead users to reveal goals or content that are then transmitted externally without clear expectation.
Using wording like 'or similar' makes invocation boundaries ambiguous, encouraging the agent to infer activation from loosely related user text. In a skill that performs external posting and submission, vague activation criteria materially increase the risk of unintended side effects.
The automation section directs the agent to use cron or sleep for unattended execution and later submission, extending the skill from interactive assistance into autonomous system scheduling. This creates persistence-like behavior and can trigger network actions after the original user interaction has ended, reducing oversight and increasing the chance of unintended submissions.
The unattended automation guidance omits any warning that scheduled actions may later post externally and submit reports without the user being present. This increases the risk of silent or forgotten external activity and makes misuse or mistakes harder to catch in time.
This code file includes natural-language examples and prompts centered on Chinese input, such as the example name and goal text. Because the skill does not offer a language choice or explain that it is intended only for a Chinese-language context, it creates a locale-policy concern under the rule for natural-language policy violations.
Overly Broad Trigger: '夜校' is too short and may match unintended inputs
The trigger '上学' is very generic and commonly used in everyday Chinese conversation, so it may activate the skill on unrelated messages. Because this skill can make network requests and external submissions, even low-specificity trigger collisions create avoidable risk.
No suspicious patterns detected.