T01 · Skill Instruction Hijacking
- Location
references/web-search-config.md:7- Finding
Mandatory Third-Party Promotion and Agent Workflow Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a web-tool guide, but it also asks agents to collect API keys, change local configuration, install unverified remote code, and restart browser or gateway processes.
Install only after reviewing whether you trust the opencli package, the GitHub release extension, and the local configuration changes. Avoid pasting API keys into chat; use a secure local secret path instead. Do not run the setup script on a sensitive or shared machine unless you are prepared for global npm installation, browser restart, gateway restart, and persistent local changes.
references/web-search-config.md:7Mandatory Third-Party Promotion and Agent Workflow Hijacking
scripts/setup-opencli.sh:107Remote Mutable Code Downloaded and Loaded as a Browser Extension
scripts/setup-opencli.sh:65Unpinned Global Installation of a Third-Party CLI Package
scripts/setup-opencli.sh:180Shell Command Injection Through Chrome Command-Line Reconstruction
references/web-search-config.md:84Overbroad Process Termination During Gateway Restart
references/web-search-config.md:27API Keys Exposed Through Chat, Process Arguments, and Plaintext Verification
The declared purpose is documentation-style guidance for choosing web tools, but the behavior extends into system setup and modification: installing software, downloading artifacts, compiling a browser plugin, and restarting the browser. That mismatch is dangerous because users or orchestrators may trust the skill as harmless guidance while it can trigger privileged local changes and external code supply-chain exposure.
The skill references shell execution capability by instructing the agent to run a setup script (bash {baseDir}/scripts/setup-opencli.sh) but does not declare any tool scope or permissions boundary. This creates an authorization gap: a guidance skill can induce command execution and environment modification without explicit least-privilege declaration, increasing the chance of unintended or unsafe system changes.
The trigger phrases are excessively broad and include everyday terms like 搜索/上网/查资料/web search/fetch/browser/opencli, making the skill likely to auto-activate in many normal conversations. Because the skill contains operational instructions including shell-based setup and mandatory workflow constraints, over-triggering expands the attack surface and can steer unrelated tasks into risky tool use or setup actions.
The skill's natural-language instructions are entirely in Chinese and provide no option for the user or agent to choose another language. This creates a locale/language policy issue because the skill effectively mandates one language without documenting user opt-in or a justified region-specific constraint.
The entire instruction set and required user-facing messages are written in Chinese, including directives to output text verbatim to the user. There is no indication that the skill is region-specific or that users may opt into another language, which makes this a natural-language locale policy issue.
The skill asks the agent to collect a user's API key and store it persistently without clearly disclosing that the secret will be written to local configuration and remain accessible afterward. This creates a credential-handling risk because users may provide secrets without informed consent, and persisted keys may later be exposed through logs, config reads, backups, or other tools.
The guide instructs the agent to solicit, store, and later reuse a user-provided API key, turning the skill into a credential collection and persistence workflow. In an adversarial or misconfigured environment, this broadens secret exposure and normalizes handing sensitive credentials to the agent rather than using a secure provisioning path.
The guide directs the agent to run local configuration and service-management commands that persist a user-supplied API key and modify runtime state. In an agent-skill context, instructions to write secrets into config files and restart infrastructure exceed normal content guidance and can lead to unauthorized system changes, credential exposure, or denial of service if triggered inappropriately.
The restart section includes Docker restart and process-kill commands such as pkill, which can disrupt unrelated workloads and create avoidable downtime. Embedding operational control actions inside a web-search helper skill is dangerous because a routine user request failure could cascade into service interruption on the host.
The later verification step explicitly tells the agent to read back stored API keys from configuration after wake-up, increasing the number of times the secret is accessed and the chance it is surfaced to the model, logs, or other components. Secret retrieval for verification is especially risky because it normalizes exposing credential material rather than checking only metadata such as whether a key is present.
The script downloads executable browser-extension content from a remote GitHub release and installs it without verifying a cryptographic checksum, signature, or pinned immutable artifact. If the release asset, repository, network trust path, or dependency source is compromised, a malicious extension could be installed into the browser and execute with the user's browser privileges.
if [ -n "$version" ]; then
download_url="${GITHUB_RELEASE_BASE}/download/v${version}/opencli-extension.zip"
info "尝试下载 Browser Bridge 插件 v${version}..."
if curl -fsSL --max-time 60 -o "$tmp_zip" "$download_url" 2>/dev/null; then
downloaded=true
else
warn "v${version} 下载失败,回退到 latest release"
The script explicitly kills the detected Chrome process and escalates to SIGKILL if it does not exit, which can disrupt active browsing sessions and risk unsaved user state. Although there are informational log messages, there is no confirmation prompt or explicit user warning before this destructive action is taken.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
info "使用新参数重新启动 Chrome..."
# 后台启动,重定向输出到日志文件
local log_file="/tmp/opencli-chrome-restart.log"
nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 &
local new_pid=$!
info "Chrome 已启动 (PID: ${new_pid}),日志: ${log_file}"
This manifest-like JSON uses natural-language descriptions that frame the resource set as Chinese-oriented, and several entries explicitly prescribe preferred language choices such as '中文首选' and '中文版'. That can conflict with a language/locale neutrality policy because it steers agent behavior toward a specific locale without indicating user choice or opt-in.
The description '百度搜索(中文首选)' explicitly directs a preferred engine based on language/locale. Because the file does not indicate that this preference is user-selected or limited to a justified regional context, it is a natural-language locale policy concern.
The description labels this as 'MDN Web Docs 搜索(中文版)', which steers use toward a specific language version. Without an explicit opt-in or justification that this skill is region-specific, this is a natural-language locale preference violation.
The script's comments and user-visible status/error messages are written in Chinese throughout, with no option to select another language. This creates a locale/language policy concern because the skill imposes a specific language on all users without opt-in or documented regional scoping.
No suspicious patterns detected.