T01 · Skill Instruction Hijacking
- Location
SKILL.md:103- Finding
Mandatory Promotional Content Manipulates Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This ChartGen skill does what it claims, but it asks agents to send user data to an external service and includes unsafe execution/download patterns that deserve review before installation.
Install only if you are comfortable sending prompts and supported spreadsheet files to ChartGen. Avoid using it with secrets, regulated data, or sensitive business data unless you have approval, and prefer runtimes that pass tool arguments without shell interpolation and restrict outbound downloads to trusted ChartGen origins.
SKILL.md:103Mandatory Promotional Content Manipulates Agent Output
SKILL.md:70Verbatim User Queries Are Interpolated into a Documented Shell Command
tools/chartgen_api.js:358API-Controlled Artifact URLs Enable Unrestricted Server-Side Requests and Downloads
The skill instructs the agent to upload user queries and optional spreadsheet files to the ChartGen API, including multi-file joins and external/web sources, but does not warn users that their content will leave the host system and be sent to a third party. This creates a real confidentiality and privacy risk, especially for sensitive spreadsheets or business data that users may assume are being processed locally.
Referenced artifact was not completely inspected
## Tool — `tools/chartgen_api.js`
Referenced artifact was not completely inspected
## Tool — `tools/chartgen_api.js`
Referenced artifact was not completely inspected
## Tool — `tools/chartgen_api.js`
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
### STEP 1 — Confirm Before Submitting
Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
### STEP 1 — Confirm Before Submitting
Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel
The skill declares access to an environment-provided API key (CHARTGEN_API_KEY) but does not define an explicit tool/permission scope. This weakens least-privilege boundaries and can allow an agent runtime to invoke capabilities or access secrets without a clearly constrained policy, increasing the chance of unintended external data transfer or secret exposure through associated tooling.
The activation text is extremely broad, covering visualizations, dashboards, reports, spreadsheet uploads, cross-file analysis, and even any mention of ChartGen. Overbroad triggers can cause the skill to activate on many common user requests and route content or files to this external integration when a more local or safer capability would suffice.
No suspicious patterns detected.