T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Mandatory workflow overrides user intent and forces remote upload
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This IELTS review skill has a real study use, but it also auto-updates itself, uploads review data, stores long-lived tokens, scans broad personal folders, and can run production deployment commands with insufficient user control.
Review this carefully before installing. Disable or remove the prompt auto-update hook, avoid author mode on machines with production SSH access, use a dedicated short-lived token stored outside shell startup files, require explicit confirmation before any upload or folder scan, and treat the README's offline claims as stale because the current skill is web-connected.
SKILL.md:12Mandatory workflow overrides user intent and forces remote upload
hooks/auto-update.sh:17Prompt hook performs unattended remote Skill replacement
scripts/setup-client-mode.sh:187Long-lived account token is persisted in plaintext shell startup files
scripts/generate-pdf.js:13PDF generation sends opt-out telemetry to an operator-controlled endpoint
assets/review-template.html:631Generated pages execute an unpinned third-party script from a public CDN
scripts/scan-legacy-reviews.js:191Default legacy-review discovery traverses broad personal directories
SKILL.md:447IELTS review Skill exposes excessive production deployment authority
This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.
## Category 11: Category-Membership Reasoning Treated as Inference
**Description:** When the passage establishes "Category A has property B" and then states "X belongs to Category A", concluding "X has property B" is **direct information**, not inference. The test-taker wrongly treats this as over-inference and chooses NOT GIVEN.
**Examples:**
- Passage: "Shade-tolerant plants have lower growth rates" + "Eastern hemlock is shade-tolerant" → Eastern hemlock has lower growth rates. This is NOT inference — it's stated through category membership.
- Test-taker chose NOT GIVEN thinking "the passage doesn't directly say eastern hemlock has lower growth rates"
**Key Rule:** If the passage says "A-type things have X" and "Y is A-type", then "Y has X" is **a stated fact**, not inference. This is TRUE/FALSE territory, not NOT GIVEN.
**Improvement:** When you're leaning toward NOT GIVEN, check: did the passage put the subject into a category that was already described? If yes, the category's properties apply.
This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.
## Category 11: Category-Membership Reasoning Treated as Inference
**Description:** When the passage establishes "Category A has property B" and then states "X belongs to Category A", concluding "X has property B" is **direct information**, not inference. The test-taker wrongly treats this as over-inference and chooses NOT GIVEN.
**Examples:**
- Passage: "Shade-tolerant plants have lower growth rates" + "Eastern hemlock is shade-tolerant" → Eastern hemlock has lower growth rates. This is NOT inference — it's stated through category membership.
- Test-taker chose NOT GIVEN thinking "the passage doesn't directly say eastern hemlock has lower growth rates"
**Key Rule:** If the passage says "A-type things have X" and "Y is A-type", then "Y has X" is **a stated fact**, not inference. This is TRUE/FALSE territory, not NOT GIVEN.
**Improvement:** When you're leaning toward NOT GIVEN, check: did the passage put the subject into a category that was already described? If yes, the category's properties apply.
The README describes receiving a token via a localhost callback and automatically writing it to ~/.zshrc, which creates credential persistence in a shell profile and modifies a sensitive startup file without prominent warning or safer storage guidance. If the token is long-lived or the profile is readable, this can expose credentials to other local processes, users, logs, backups, or later command output.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The skill includes credential acquisition and persistence behavior—guiding token extraction from browser storage and writing credentials into shell startup files—even though this is not a normal expectation for a reading-review tool. Credential handling expands the trust boundary substantially and risks accidental leakage, misuse, or persistence of sensitive tokens beyond the immediate task.
The auto-scan/batch-import activation language is broad and encourages scanning the user's computer for historical notes without tight bounds. In context, this is more dangerous because the skill directs sweeping searches across Documents, Desktop, Downloads, and iCloud-like locations, which can expose unrelated personal data during an unexpectedly triggered workflow.
The auto-scan/batch-import activation language is broad and encourages scanning the user's computer for historical notes without tight bounds. In context, this is more dangerous because the skill directs sweeping searches across Documents, Desktop, Downloads, and iCloud-like locations, which can expose unrelated personal data during an unexpectedly triggered workflow.
Referenced artifact was not completely inspected
> **v3.9.1 新增**:Step 0 自动版本检查(scripts/check-update.js),每次激活时比对本地与 ClawHub 版本。
Referenced artifact was not completely inspected
> **v3.9.1 新增**:Step 0 自动版本检查(scripts/check-update.js),每次激活时比对本地与 ClawHub 版本。
The skill references direct use of SSH private key material and known-host configuration to access a remote server. Guidance that depends on local credential files inside a general-purpose skill increases the chance of credential misuse, accidental disclosure, or unauthorized reuse if the skill is invoked in the wrong environment.
scp -o ConnectTimeout=15 \
-o StrictHostKeyChecking=accept-new \
-o UserKnownHostsFile=~/.ssh/known_hosts_cfd \
-o "ProxyCommand=/Users/dengjiawei/bin/cloudflared access tcp --hostname ssh.tuyaya.online" \
-i ~/.ssh/workbuddy.pem \
<本地文件> ubuntu@ssh.tuyaya.online:/var/www/ielts/
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 用 getReviews 回查本篇是否真的入库(替换 BOOK/TEST/PASSAGE)
curl -s https://www.liuxue.online/api/ielts -H 'Content-Type: application/json' \
-d '{"action":"getReviews","token":"<USER_TOKEN>","book":<BOOK>,"test":<TEST>}' \
| python3 -c "
import json,sys
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
}, ensure_ascii=False)) " "$JSON_FILE" "$TOKEN")
curl -s -X POST https://www.liuxue.online/api/ielts
-H 'Content-Type: application/json'
-d "$PAYLOAD"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
}, ensure_ascii=False)) " "$JSON_FILE" "$TOKEN")
curl -s -X POST https://www.liuxue.online/api/ielts
-H 'Content-Type: application/json'
-d "$PAYLOAD"
The batch-import workflow promotes automatic scanning of multiple broad areas of the user's computer to locate review files. This is risky because it normalizes wide filesystem discovery in a study skill, potentially exposing unrelated documents, filenames, or synchronized cloud content far beyond the least-privilege needed for the task.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
TOKEN=$(cat ~/.ielts-tuyaya-token | python3 -c "import json,sys; print(json.load(sys.stdin)['token'])")
curl -s 'https://www.liuxue.online/api/ielts' -H 'Content-Type: application/json' \
-d "{\"action\":\"getReviews\",\"token\":\"$TOKEN\",\"book\":<BOOK>,\"test\":<TEST>}" \
| python3 -c "import json,sys; d=json.load(sys.stdin); recs=[r for r in d.get('data',[]) if r['book']==<BOOK> and r['test']==<TEST>]; print('✅ 已入库篇目:', [(r['passage'], r['score'], r['total']) for r in recs])"
The matcher includes very broad terms such as 'IELTS', '复盘', and '错题分析', so normal educational requests can silently trigger the hook. This increases the chance of unexpected code execution and makes exploitation easier because an attacker only needs to induce a matching phrase rather than a deliberate command.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# ──────────────────────────── 服务端二次校验 ────────────────────────────
echo ""
echo "🔍 校验 token 有效性..."
RESP=$(curl -s -X POST "$API_BASE" \
-H 'Content-Type: application/json' \
-d "{\"action\":\"getUserInfo\",\"token\":\"$TOKEN\"}")
The README explicitly states '纯离线模式' and '不再依赖任何远程 API', which communicates a local-only scope. However, the same document describes opening a browser to liuxue.online for OAuth-style authorization and importing/uploading review data to the web system, so the declared behavior and actual documented operations are inconsistent.
A broad trigger like '帮我复盘' can cause the skill to activate during ordinary conversation without clear user intent, increasing the chance of unintended processing, file generation, or downstream upload/auth flows. In an agent environment with side effects, ambiguous invocation raises the risk of accidental data handling and overbroad task execution.
The stated intent for the skill is that structured JSON is deployed to the server and rendered by review.html, with 'No standalone HTML generation needed.' In contrast, the README presents local review HTML generation as a standard artifact and even describes HTML templates and browser viewing as primary workflow components, which directly conflicts with that intent.
The skill exercises broad capabilities—shell, filesystem access, environment-variable access, and network transmission—but does not declare an explicit tool scope or permissions boundary. That makes it easier for the skill to invoke powerful operations implicitly, reducing user visibility and increasing the chance of overreach or misuse if the trigger fires unexpectedly.
Detected: suspicious.dangerous_exec