T01 · Skill Instruction Hijacking
- Location
SKILL.md:17- Finding
Mandatory Injection of Server-Controlled Links into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s Temu research purpose is coherent, but it requires unvalidated service-provided links in user answers and can fetch then upload arbitrary image URLs, so it should be reviewed before installation.
Install only if you trust GeekBI’s API responses and are comfortable with the skill storing login state in your user configuration directory. Treat all returned clickable links and login/action links as third-party service-provided destinations, and avoid giving image URLs that point to localhost, private networks, internal dashboards, or sensitive local files.
SKILL.md:17Mandatory Injection of Server-Controlled Links into Agent Responses
scripts/geekbi_auth.py:585Unvalidated Server-Controlled Authentication and Action Redirects
scripts/temu_image_search.py:111Arbitrary Image URL Fetching Enables SSRF and External Disclosure of Retrieved Data
If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.
If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.
If the skill actually performs local persistence of login state, token management, and authentication flows outside its declared Temu research purpose, it creates hidden behavior that users and reviewers may not expect. Undisclosed auth handling can expose sensitive tokens, leave durable state on disk, and expand the attack surface beyond simple data analysis.
Without declared permissions the skill's intent is opaque and cannot be validated.
Overly broad trigger phrases can cause the skill to activate in conversations that only loosely resemble Temu research, increasing the chance it accesses external services or routes user data unnecessarily. In an agent ecosystem, overbroad invocation widens the effective attack surface and can lead to unintended data handling without clear user intent.
The instructions require the skill to '默认使用简体中文' and to use only Chinese business names for user-facing output. This imposes a language policy on users without offering a choice or opt-in, which is a natural-language locale policy violation under the stated rules.
The display name, short description, and default prompt are all written exclusively in Chinese, which indicates the skill is effectively constrained to a specific language/locale. There is no visible opt-in, language selection mechanism, or documented justification that this skill is intentionally region-specific, so this creates a natural-language policy concern.
Line L10 states that the skill should default to Simplified Chinese output. Under the policy criteria, language constraints should not be imposed without user opt-in or an explicit choice mechanism, and this file does not indicate such a choice is offered.
Line L65 instructs that when the server returns a top-level msg, the skill must show only that Chinese text to the user. This imposes a specific language on user-facing output without offering language choice or documenting a justified locale restriction, which matches the language/locale policy violation category.
L117 明确要求“面向用户只提示该中文文案”,这构成了固定语言输出约束。根据规则,若未提供语言/locale 选择或未说明这是合理的区域限定工具,则属于自然语言政策违规。
L134 明确要求“面向用户只提示该中文文案”,这属于自然语言层面的固定语言要求。文档中没有说明可根据用户语言偏好切换,也没有给出用户选择语言的选项,因此存在语言/locale 策略违规风险。
The instruction requires presenting results to users using Chinese business names and avoids exposing original command/parameter forms. This imposes a specific language/locale behavior without offering the user a choice or documenting opt-in, which matches the policy's language/locale violation criterion.
The instruction says to use the server-returned Chinese message to prompt the user, which imposes a specific language on user-facing output. The file does not offer user opt-in, fallback language handling, or a documented region-specific justification for requiring Chinese.
The file instructs the skill to use script-generated Chinese errors when no valid server prompt exists. This is a natural-language locale requirement that applies regardless of user preference and is not justified as a region-specific constraint.
This code file contains multiple natural-language strings in Chinese for its docstring, CLI description, help text, and error messages. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.
User-facing docstrings, argument descriptions, and error messages are written only in Chinese. This effectively forces a specific language for all users, and the file does not provide opt-in language selection or explain that the skill is intentionally limited to a Chinese-speaking audience.
This code file contains natural-language strings such as the module docstring, argument descriptions, and error messages only in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not documented here.
The file's docstring, CLI help text, and runtime error/output messages are all written in Chinese, which imposes a specific language on users. The policy allows locale constraints when user choice or clear justification is provided, but this script does not offer an opt-in or document that it is intentionally limited to Chinese-speaking users.
The README says '安装后直接用中文描述目标即可', which imposes Chinese as the interaction language in the skill description. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless alternatives or justification are provided.
The instructions state that the skill should default to Simplified Chinese and that progress updates, analysis, and final responses should use Chinese business terms. This is a natural-language locale constraint that applies regardless of user preference, and the file does not indicate a user choice or opt-in mechanism.
The instructions require the skill to default to Simplified Chinese and further require progress updates, analysis, and final responses to be in Chinese. This is a natural-language locale policy constraint presented without offering the user a language choice or opt-in.
The instructions state that responses, progress updates, and final answers should use Chinese by default, and technical information should also be hidden unless explicitly requested. This is a natural-language locale policy constraint that does not offer the user a language choice or opt-in.
Line L08 states '默认使用简体中文和绝对日期', which imposes a specific language default in the skill instructions. Under the policy rule, forcing a language or locale without explicit user opt-in can be a natural-language policy violation unless a justified regional constraint is documented.
This Python skill uses Chinese-only natural-language descriptions and user-facing messages throughout, starting with the module docstring and continuing in CLI/help text, without offering a language choice or documenting that the skill is intended only for a Chinese-speaking environment. That creates a locale-policy concern under the rule for natural-language policy violations.
The script accepts arbitrary http/https URLs and local file paths, then reads and uploads the resulting image content to an external API. In an agent/skill context, this can enable SSRF-like access to internal network resources or unintended exfiltration of local files if user-controlled input is passed through without clear trust boundaries or consent prompts.
No suspicious patterns detected.