T01 · Skill Instruction Hijacking
- Location
SKILL.md:162- Finding
Untrusted Web AI Responses Can Direct Local Code and Command Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent, but it gives third-party web AIs and browser-automation tools a very broad path to influence local actions and authenticated browser sessions.
Install only if you are comfortable letting this skill control a browser session and use external web AI output to guide local execution. Use a dedicated browser profile logged in only to the chosen AI site, avoid sharing secrets or private code unless intentional, review every command/download/file write before approval, and prefer pinned/verified tool versions over latest-release installs.
SKILL.md:162Untrusted Web AI Responses Can Direct Local Code and Command Execution
references/tool-installation.md:17Unpinned Third-Party Bridge and Browser Extension Are Installed and Trusted
references/gecko-automation.md:25Automation Reuses the User's Primary Authenticated Browser Profile
references/gecko-automation.md:69Predictable Unauthenticated Local WebDriver Endpoint Exposes Browser-Control Capability
The overview says the local agent will create files, run scripts, download resources, and perform searches, but it lacks a clear up-front warning that the skill can modify the local system. Users reading only the description may not realize the skill can install tools, alter config files, write to disk, and execute downloaded code, which undermines informed consent.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `POST /session/{id}/element/{el}/click` | 点击元素 |
| `POST /session/{id}/element/{el}/value` | 输入文本 |
| `GET /session/{id}/screenshot` | 截图(base64) |
| `DELETE /session/{id}` | 关闭会话 |
Python 示例(仅标准库 urllib):
The README promotes a loop where a web AI produces steps and code while the local agent performs file creation, script execution, downloads, scraping, and web searches, yet it lacks a strong warning about possible system modification, malware introduction, data loss, or unwanted network activity. This is especially risky because it combines untrusted third-party model output with privileged local actions.
The README explicitly describes forwarding user requirements to web-based third-party AIs, but does not present a clear privacy warning about disclosure of prompts, files, code snippets, or sensitive business data to external providers. In this skill's context, that omission is dangerous because the entire workflow depends on transmitting user content outside the local agent boundary.
The trigger guidance is broad enough that ordinary requests like 'open a web AI and collaborate' may activate a workflow that relays prompts to third-party AI sites and drives local execution. That creates an unsafe scope boundary: users may invoke the skill without understanding that their data may be sent externally and that the local agent may perform impactful actions based on external model output.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
<a id="installing-the-driver-tools-when-missing-en"></a>
## Installing the Driver Tools (When Missing)
**Principle**: Agent installs its side automatically (with your consent) + you complete the browser side manually (plain‑language guidance). **Never installs without asking.**
### Channel A: Chromium → chrome-mcp (mcp-chrome)
The skill explicitly instructs the agent to run shell commands, install software, edit configuration, download binaries, and drive browsers, but it declares no tool scope restrictions. That mismatch increases the chance the skill runs with broader-than-necessary capabilities, making accidental or unsafe command execution more likely if the workflow is triggered incorrectly or influenced by untrusted web AI output.
The overview says the local agent will create files, run scripts, download resources, and perform searches, but it lacks a clear up-front warning that the skill can modify the local system. Users reading only the description may not realize the skill can install tools, alter config files, write to disk, and execute downloaded code, which undermines informed consent.
The trigger phrases include broad concepts such as '网页版 AI', '节省 tokens', and asking another AI to plan while the local agent executes, which are common conversational intents. This can cause the skill to activate in contexts where the user did not intend browser automation, third-party data transfer, or local execution, increasing the risk of unintended actions.
The initial protocol message normalizes the idea that the agent will provide the user's requirements to the external web AI, making disclosure the default behavior. While this is central to the skill's design, presenting it as a standard first step without a privacy warning or minimization requirement increases the chance of oversharing sensitive user content.
The instruction to forward the user's requests 'in full' to a web AI creates a direct natural-language exfiltration channel to an external service. In this skill's context, the external model is intentionally used as a planning copilot, so unredacted prompts may include secrets, proprietary code, internal paths, logs, or personal data that do not need to leave the local environment.
The entire skill documentation is written in Chinese and does not indicate that another language can be used or that the locale is intentionally constrained. Under the policy rule for language/locale, this is a natural-language constraint presented without user opt-in or documented justification.
The file title and all instructional content are written exclusively in Chinese, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.
The skill instructions force a single language presentation throughout the file and do not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, a fixed language without opt-in or justification is a natural-language policy concern.
The instructions tell the user to install and connect a browser-control extension and explicitly state that the agent will then be able to control the browser, but they do not provide a clear warning about privacy, session exposure, or the risk of the agent accessing logged-in web content. In this skill’s context, that omission is more dangerous because the whole purpose is to drive a real user browser containing live accounts, cookies, and sensitive data across multiple AI services.
This code file contains natural-language instructions, usage text, and output field explanations that force a specific language/locale for users. The policy requires flagging language or locale constraints when the skill does not offer opt-in or justify the restriction as region-specific.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
import subprocess # noqa: PLC0415
out = subprocess.run(
[
"/System/Library/Frameworks/CoreServices.framework/Frameworks/"
"LaunchServices.framework/Support/lsregister",
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
import subprocess # noqa: PLC0415
out = subprocess.run(
["xdg-settings", "get", "default-web-browser"],
capture_output=True,
text=True,
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
permit persons to whom the Software is furnished to do so.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
No suspicious patterns detected.