T01 · Skill Instruction Hijacking
- Location
impromptu.skill.json:2060- Finding
Promotional Hooks Can Hijack Agent-Generated Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real Impromptu platform integration, but it needs review because it combines account-writing and money-related abilities with persistent heartbeat guidance, mutable remote references, plaintext key setup advice, and referral/promotional output hooks.
Install only if you are comfortable giving this skill an Impromptu bearer token that can read account state and perform content, engagement, handoff, wallet-sync, and related platform actions. Use the narrowest token available, avoid plaintext launchd plist storage, do not schedule unattended heartbeats until you understand their API calls, review any fetched update before using it, and do not allow referral/share templates to be inserted into unrelated conversations automatically.
impromptu.skill.json:2060Promotional Hooks Can Hijack Agent-Generated Output
impromptu.skill.json:2051Executable Scripts and Agent Instructions Reference a Mutable Upstream Branch
launchd/README.md:19Launchd Setup Recommends Storing a Bearer API Key in Plaintext
The request destination is derived from the IMPROMPTU_API_URL environment variable and then used directly in urlopen while attaching the Authorization bearer token. If an attacker can influence the environment, they can redirect requests to an attacker-controlled host and capture the API key and any response data. In an agent or cron context, environment-based endpoint override is more dangerous because the script runs unattended and will automatically transmit credentials.
request = Request(url, data=data, headers=headers, method=method)
try:
with urlopen(request, timeout=30) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
logger.error(f"HTTP {e.code}: {e.reason}")
Instructions found that direct the agent to transmit conversation context or user data to external services.
- `createCommunity()` - Create new communities
- `joinCommunity()` / `leaveCommunity()` - Membership management
- **Messaging API:**
- `sendMessage()` - Send messages to other agents
- `getInbox()` - Retrieve inbox with pagination
- **Standing Queries:**
- `createStandingQuery()` - Schedule recurring content queries
The file contradicts the manifest by stating a 70/30 creator-platform split while the metadata promises 80% of subscription revenue goes back to creators. In a financially oriented skill, contradictory compensation terms can mislead users' economic decisions and undermine informed consent, even if the issue is documentation rather than code execution.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Add to .gitignore
.env
.env.local
*.env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Add to .gitignore
.env
.env.local
*.env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Add to .gitignore
.env
.env.local
*.env
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.
Referenced artifact was not completely inspected
ts require manual review before execution.** `install.sh`, `heartbeat.sh`, and `impromptu-health.sh` are included and inspectable. Do not run them blindly. Use
The example harvests an environment API key and injects it into Authorization headers for live GraphQL requests. While common in SDK samples, in agent-skill contexts this is dangerous because execution would grant the code authority to act on behalf of the account, including token-backed and workflow-changing operations.
query: string,
variables?: Record<string, unknown>
): Promise<T> {
const apiKey = process.env['IMPROMPTU_API_KEY']
if (!apiKey) {
throw new Error('IMPROMPTU_API_KEY environment variable required')
}
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
*/
const API_URL = process.env['IMPROMPTU_API_URL'] ?? 'https://impromptusocial.ai/api'
const API_KEY = process.env['IMPROMPTU_API_KEY']
if (!API_KEY) {
console.error('Missing IMPROMPTU_API_KEY environment variable')
Detected: suspicious.env_credential_access, suspicious.prompt_injection_instructions