T01 · Skill Instruction Hijacking
- Location
scripts/report_generator.py:164- Finding
Forced Third-Party Commercial Promotion in Generated Reports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a credit-check/reporting skill, but its official-source claims, fail-open scoring, and embedded promotional contact create review-worthy trust risks.
Review carefully before installing. Do not rely on generated reports for credit, lending, procurement, or compliance decisions unless live source checks, authorization, provenance, and missing-data handling are fixed. Remove the hardcoded promotional contact and require HTTPS and explicit user authorization.
scripts/report_generator.py:164Forced Third-Party Commercial Promotion in Generated Reports
scripts/risk_calculator.py:76Missing Credit-Check Data Fails Open and Produces Favorable Scores
SKILL.md:48Judicial Execution Lookups Are Directed to a Plaintext HTTP Endpoint
The skill claims to perform authoritative enterprise credit checks using official government and PBOC sources, yet the documented behavior does not demonstrate real integrations and appears to produce a report template that could be mistaken for genuine official-source output. In a paid credit-assessment context, this creates a serious integrity and trust risk: users may make lending, procurement, or due-diligence decisions based on fabricated, simulated, or unverifiable data presented as official findings.
The report generator claims to produce a credit-check report from computed results, but most narrative sections and conclusions are hardcoded as favorable outcomes regardless of the actual input data. In a due-diligence or credit decision workflow, this can misrepresent risk, mislead operators into approving unsafe counterparties, and undermine trust in the tool's output.
The validation/output section states that the sample computes to 100 points and low risk, but the provided litigation score logic would make the sample's total lower than 100. This creates false assurance that the scoring implementation is correct, increasing the likelihood that flawed scoring and reporting logic ships unchecked into production.
The activation criteria are overly broad and may trigger the skill for many general business, due-diligence, or background-check requests without sufficient scoping, consent, or eligibility checks. In this context, over-triggering is risky because the skill deals with sensitive credit and legal-risk judgments, increasing the chance of inappropriate use, excessive data collection, or users receiving quasi-authoritative risk outputs when they did not explicitly request regulated credit-style checks.
The skill describes collecting enterprise identifiers and performing external lookups across official sites but does not prominently warn about sensitive data handling, authorization requirements, or the compliance implications of querying regulated credit information. In a credit-reporting workflow, missing warnings increase the likelihood of unauthorized queries, improper sharing of sensitive business information, and user misunderstanding about legal restrictions.
This markdown file is written entirely in Chinese, beginning with the title at L01, and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file is entirely written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
This Python file embeds all user-facing natural-language content, comments, and generated report text in Chinese, including console output and the full report template. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
This code embeds the skill name and user-facing report content in a single fixed language, Chinese, with no indication that users can select another language or opt in to this locale. The policy requires flagging language or locale constraints when they are forced without user choice or explicit justification.
The report generator embeds unrelated marketing/contact solicitation directly into a credit-check report, which mixes compliance-sensitive output with promotional content. In a due-diligence or enterprise risk context, this can undermine trust, create conflicts of interest, and expose users to unauthorized off-platform contact or social-engineering style follow-up.
This code file contains user-facing natural-language descriptions and docstrings only in Chinese, including the module title and function documentation. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.
This markdown template forces a single language/locale for all users, and there is no natural-language note offering an alternative language or stating that the template is intended only for a Chinese-speaking or region-specific context. Under the policy, fixed language without opt-in or justification is a reportable locale-policy issue.
The entire template, including headings, field labels, recommendations, and disclaimer text, is written exclusively in Chinese. For a general-purpose skill artifact, this imposes a specific language/locale without any visible option for user selection or documented justification, which matches the language/locale policy concern.
This Python test file contains natural-language docstrings, assertion messages, comments, and console output entirely in Chinese, which imposes a specific language on users and maintainers. Under the policy rule, locale-specific language is a finding when the skill does not provide opt-in or document that the skill is intentionally region-specific.
All user-facing instructions, output templates, and invocation description are presented exclusively in Chinese, and the file does not state that the skill is China-specific or otherwise limited to Chinese-language use. Under the policy, forcing a specific language without opt-in can be a locale/language policy issue unless the constraint is explicitly documented and justified.
The manifest describes this skill as a tool for performing enterprise credit checks and generating a report based on official data sources. The contact section invites users to seek '信用修复' and '深度尽调', which are separate advisory or remediation services rather than part of the declared checking/reporting function.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and data descriptions only in Chinese, with no opt-in, alternative language, or explicit justification that the skill is limited to a Chinese-speaking or China-specific compliance context.
No suspicious patterns detected.