T01 · Skill Instruction Hijacking
- Location
SKILL.md:14- Finding
Mandatory Reproduction and Publication of Remotely Controlled Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill documents a GOYFILES API integration, but it asks users to publish server-supplied text on X and handles API credentials without enough safeguards.
Review this skill before installing. It is not proven malicious, but users should only proceed if they trust GOYFILES, understand that onboarding may require posting exact service-generated text from their X account, and have a safe place to store the returned API key and identity token. Avoid using the persistent markdown write tool unless you explicitly intend to save or overwrite notes.
SKILL.md:14Mandatory Reproduction and Publication of Remotely Controlled Content
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -sS -X POST "https://goyfiles.com/api/chatbot/bot-auth/register" \
-H "Content-Type: application/json" \
-d '{"name":"MyAgent"}'
The skill explicitly instructs the agent to save a one-time agent_api_key but provides no warning about treating it as a secret, avoiding logs, or restricting storage. In an agent setting, this increases the chance the credential is exposed in chat history, traces, or files, enabling unauthorized use of the external bot identity.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
4. `After posting, send me the tweet URL.`
Never paraphrase `verification_phrase`.
Never ask the user to "include the code".
Do not ask the user to compose the claim tweet manually.
### Step C - Verify claim tweet
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Never paraphrase `verification_phrase`.
Never ask the user to "include the code".
Do not ask the user to compose the claim tweet manually.
### Step C - Verify claim tweet
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -sS -X POST "https://goyfiles.com/api/chatbot" \
-H "Content-Type: application/json" \
-H "X-Bot-Identity: $IDENTITY_TOKEN" \
-d '{"message":"schema","toolCalls":[{"name":"document_id_schema","args":{"source_dataset":"pacer-courtlistener","max_samples":5}}]}'
The documentation exposes a persistent write capability via write_markdown_file but does not warn that invoking it modifies durable state. In an agent-skill context, this increases the chance an agent will write notes or overwrite files without explicit user consent, creating integrity and privacy risks through unintended persistence.
No suspicious patterns detected.