T01 · Skill Instruction Hijacking
- Location
SKILL.md:58- Finding
Mandatory bypass of built-in network safety controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent video-workflow generator, but it needs review before installation because it routes agents through its own broad network fetchers, handles credentials, and persists/propagates generated workflow state.
Install only if you trust the publisher and are comfortable with a skill that uses local network fetching instead of built-in web tools. Use dedicated low-privilege API keys, verify every configured gateway hostname, avoid HTTP endpoints except intentional localhost hotlist use, keep Douyin session files and .env files out of shared repos/backups, and do not let generated finance workflows produce personalized trading advice without compliance review.
SKILL.md:58Mandatory bypass of built-in network safety controls
scripts/web_search.py:196Unrestricted full-page fetch permits server-side request forgery and local file access
scripts/web_search.py:66Credentials and user content can be transmitted to arbitrary configured gateway origins
scripts/scrape_douyin.py:113Reusable Douyin browser authentication state is persisted without adequate protection
scripts/requirements-douyin.txt:4Unpinned packages and unverified external executable code create supply-chain exposure
The script builds the request URL from DAILYHOT_API_BASE sourced from an environment variable or local .env file and then performs a network request without validating the scheme, host, or destination. If an attacker can influence that configuration, they can redirect requests to arbitrary internal or external endpoints, creating an SSRF-style primitive and causing the tool to trust attacker-controlled JSON responses.
"""拉单个平台热榜,返回 (title, [items])。失败抛异常,绝不吞掉。"""
url = "%s/%s" % (base, platform)
req = urllib.request.Request(url, headers={"User-Agent": "peanutcut-hotlist/1.0"})
with urllib.request.urlopen(req, timeout=timeout) as resp:
payload = json.loads(resp.read().decode("utf-8"))
# DailyHotApi 正常返回 {"code":200,"title":...,"data":[{title,hot,...}]}
if payload.get("code") not in (200, "200", None):
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# 复制本文件为 .env 并填入你自己的凭证;.env 已在 .gitignore 中,勿提交。
# 值只是占位符,请替换为你自己的真实凭证。
# ---- 生成器已有 ----
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env
__pycache__/
*.pyc
.DS_Store
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env
__pycache__/
*.pyc
.DS_Store
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.
The invocation description is broad enough to capture common finance-content requests, causing the skill to trigger in many situations where the user may only want generic discussion or harmless drafting help. In this context, over-broad routing is dangerous because it can steer users into a high-risk finance workflow that fetches data, creates files, and generates actionable market content without deliberate opt-in.
The exemplar directs the generated skill to produce explicit buy/sell/hold advice and price levels, which materially exceeds a workflow-builder's stated role and pushes the agent into personalized financial-advice behavior. In context, this is dangerous because downstream skills may inherit these instructions and present high-stakes investment recommendations without proper authorization, suitability checks, or compliance controls.
The skill explicitly instructs the agent to provide buy/sell recommendations and key price levels without any meaningful consent, suitability, jurisdiction, or compliance gate. Because financial decisions can cause direct monetary harm, this turns a content-creation exemplar into a mechanism for delivering unvetted actionable investment advice.
The description is written to define a Chinese-language video creation workflow for account content, but it does not offer a language choice or indicate that Chinese is optional. This can violate language/locale policy if the skill forces a specific language without explicit user opt-in.
Detected: suspicious.dynamic_code_execution