T01 · Skill Instruction Hijacking
- Location
SKILL.md:44- Finding
Agent Instructions Discourage Source Review and Request Full Authentication Cookies Through Chat
- Content
View full analysis
/data/cookies-raw.txt # (老路径兼容: /tmp/douyin/cookies-raw.txt 也行) # 2. 转 Netscape 格式 python3 $SKILL/keepalive.py inject # 3. 验证 cookie python3 $SKILL/keepalive.py check # 退出码 0 = 有效 # 4. (仅评论需要) 持久化 ab session python3 $SKILL/keepalive.py state save ``` ```markdown 如果 cookie 不存在/过期/无效,立刻停止并提示用户重新导 cookies,或把整段 cookies 直接发给你,你落盘到 `$SKILL/data/cookies-raw.txt` 然后跑 inject → check → state save。 ``` The final sentence instructs the Agent to accept a complete cookie string from the user and write it to disk. ### Technical Analysis The Skill text alters how an Agent is expected to operate in two security-relevant ways: 1. It explicitly tells the Agent not to inspect the executable source. 2. It permits the Agent to ask the user to send an entire authenticated Douyin cookie set through the conversation. Source inspection is not incompatible with the Skill's declared functionality. Discouraging it weakens the review boundary and makes it less likely that unsafe implementation details will be detected. Complete browser cookies can contain reusable session credentials. Transmitting them through a conversational channel unnecessarily exposes them to chat retention, logging, telemetry, memory, or access by operators and integrations. The Skill only needs a local cookie file; it does not need the credential value to be present in the conversation. ### Attack Path 1. The Skill is loaded into an Agent session. 2. The Agent follows the instruction not to inspect the source code. 3. The cookie check fails or no local cookie file exists. 4. Following `SKILL.md`, the Agent asks t ...[truncated 701 chars]- Remediation
View remediation
