T01 · Skill Instruction Hijacking
- Location
skills/ima-skills/ima_api.cjs:110- Finding
Remote Update Response Is Treated as Trusted Agent Instruction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The suite is a legitimate academic workflow package, but it includes overbroad browser control and credential-handling paths that need careful review before installation.
Install only if you are comfortable with a suite that can replace multiple local skills, access IMA notes and knowledge bases using your API credentials, and automate your regular Chrome session. Avoid enabling Chrome remote debugging for your daily browser profile, do not set IMA_BASE_URL or pass custom baseUrl values, review any update instructions as untrusted text, and follow your institution's AI-use disclosure rules before using the humanizer stages for academic submissions.
skills/ima-skills/ima_api.cjs:110Remote Update Response Is Treated as Trusted Agent Instruction
skills/ima-skills/ima_api.cjs:65IMA API Credentials Can Be Redirected to an Arbitrary Server
skills/academic-search/scripts/cdp-proxy.mjs:379Unauthenticated Local CDP Proxy Grants Privileged Control of the User's Browser
skills/academic-search/scripts/cdp-proxy.mjs:525Screenshot Endpoint Allows Arbitrary File Overwrite
A mandatory '去 AI 化处理' stage is explicitly presented as part of the pipeline and cannot be skipped, which strongly suggests intentional concealment of AI-generated authorship rather than transparent editing assistance. In the context of academic writing, this is especially dangerous because it can facilitate academic misconduct, policy evasion, and deceptive submission of machine-generated work as human-authored content.
The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.
The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.
The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.
The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.
The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.
The script performs recursive deletion with rm -rf on a path rooted in $HOME without first ensuring the parent target directory exists, is the expected location, and is safe to modify. If $TARGET_DIR is a symlink, points somewhere unexpected, or the workspace path has been manipulated, the installer could delete unintended directories for each listed skill.
for skill in "${DEPENDENCIES[@]}"; do
if [ -d "$SKILLS_DIR/$skill" ]; then
echo " 安装 $skill..."
rm -rf "$TARGET_DIR/$skill"
cp -r "$SKILLS_DIR/$skill" "$TARGET_DIR/"
echo " ✅ $skill 安装成功"
else
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
- "skip" -> validate skip safety; proceed if allowed
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
---
## Dashboard Output Rules
1. Produce full version when user explicitly requests it
2. **Append simplified version to checkpoint notification after each stage completion**
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
已知 DOI 或 arXiv ID 时,直接用 Semantic Scholar 精确查询:
# DOI 查询
curl -s "https://api.semanticscholar.org/graph/v1/paper/DOI:{doi}?fields=title,authors,year,abstract,citationCount,openAccessPdf"
# arXiv ID 查询
curl -s "https://api.semanticscholar.org/graph/v1/paper/ARXIV:{arxiv_id}?fields=title,authors,year,abstract,citationCount,openAccessPdf"
This pattern combines network interaction with piping data into Node for processing while creating a target in a local CDP proxy tied to the user's browser. In context, the higher risk is not the JSON parsing itself but that the recipe operationalizes browser-session automation against external sites, enabling an agent to pivot into a trusted browser context.
bash ~/.claude/skills/academic-search/scripts/check-deps.sh
# 2. 打开 Google Scholar 搜索页
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://scholar.google.com" | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")
# 3. 用搜索框搜索(GUI 方式,最稳定)
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \
This opens CNKI through a local CDP proxy and processes the returned target identifier, setting up automation over a potentially authenticated browser session. Because CNKI access may rely on institutional credentials, the context makes this materially more dangerous than ordinary external fetches.
bash ~/.claude/skills/academic-search/scripts/check-deps.sh
# 2. 打开知网检索页(KNS8 新版界面)
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://kns.cnki.net/kns8/defaultresult/index" \
| node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")
# 3. 等待页面加载(JS 渲染较慢)
The eval-based CDP commands execute arbitrary JavaScript in the target page context after establishing browser control. In an agent skill, this is a strong capability that can read page state and potentially be extended to act on behalf of the user, especially dangerous when the target may be behind login or institution-based access.
sleep 3
# 4. 填入搜索词
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \
-d 'document.querySelector("#txt_SearchText").value = "大语言模型 时序预测"'
# 5. 点击检索按钮
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 1. 打开 KNS8 检索页
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://kns.cnki.net/kns8/defaultresult/index" \
| node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")
# 2. 等待 JS 渲染(知网首次加载较慢)
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 从首页搜索框操作,不直接构造 /scholar?q= URL
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://scholar.google.com" | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")
# 等待页面加载后输入搜索词
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \
This script exposes a local HTTP API that can attach to the user's regular Chrome instance via the DevTools Protocol and then create tabs, navigate, click, upload files, take screenshots, and execute arbitrary JavaScript. In the context of an academic-search skill, that is far broader than necessary and creates a powerful browser-control bridge to the user's authenticated browsing session, enabling access to sensitive sites and data if any local agent or process can reach the proxy.
The /eval endpoint executes arbitrary JavaScript in the context of the selected browser tab using Runtime.evaluate, with no authentication, confirmation, or action restriction. Because the proxy operates against the user's real Chrome session, this can read page contents, interact with authenticated applications, and trigger privileged actions on websites the user is logged into.
Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.
| **Low** | Unlikely misuse, minimal harm potential | General education research |
| **Moderate** | Could be misused in specific contexts | Surveillance tech analysis, social manipulation studies |
| **High** | Clear potential for harm if misused | Vulnerability research, weapons-related |
| **Critical** | Should not be published without safeguards | Specific exploitation methods |
For Moderate or above: Include explicit "Responsible Use" statement
Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.
| **Low** | Unlikely misuse, minimal harm potential | General education research |
| **Moderate** | Could be misused in specific contexts | Surveillance tech analysis, social manipulation studies |
| **High** | Clear potential for harm if misused | Vulnerability research, weapons-related |
| **Critical** | Should not be published without safeguards | Specific exploitation methods |
For Moderate or above: Include explicit "Responsible Use" statement
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
- [ ] The source is suspiciously perfect (exactly supports the claim with no caveats)
The activation text is extremely broad and includes common everyday phrases like '帮我记一下' and general references to notes, files, and knowledge search. This can cause unintended invocation of a credentialed skill and route unrelated user content into external API operations, increasing the risk of data exfiltration, privacy violations, and unauthorized actions.
The skill documentation describes note creation flows but does not require a warning, preview, or explicit confirmation before persisting user-provided content. Without this safeguard, the agent may be manipulated into storing sensitive data, hallucinated content, or prompt-injected material, turning transient conversation into durable private records.
The create-note triggers include broad phrases such as 'generate note' or 'save this content as a note,' which can cause a write action from loosely phrased user input. Write operations are higher risk because an agent can persist unintended, sensitive, or prompt-injected content into the user's notes without a strong confirmation boundary.
The append flow lacks an explicit confirmation requirement even though it changes existing stored data. This makes the skill susceptible to prompt injection, accidental modification, and data integrity issues because a casual or ambiguous instruction can become a permanent alteration to a user note.
Append operations modify existing user data, and the trigger examples are too broad for such a sensitive action. An agent could append injected, mistaken, or privacy-sensitive text to the wrong note based on ambiguous phrasing, causing integrity loss and unintended persistence of harmful content.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal