T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Agent Inspection and Output Hijacking Through Skill Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill broadly matches a protected research-report search tool, but it needs Review because it handles API keys and device identifiers in under-scoped ways and includes instructions that try to limit inspection and force response text.
Install only after reviewing the source and accepting that this skill stores an API key locally, may ask for API-key material through chat, sends credentialed requests to configured gateways, and uses a MAC-derived device identifier during authorization. Prefer a version that uses a secure secret handoff, random short-lived device nonces, a fixed gateway allowlist, and clearer inspection-friendly instructions.
SKILL.md:9Agent Inspection and Output Hijacking Through Skill Instructions
skill-entry.js:1Undisclosed MAC-Address-Derived Device Fingerprinting
skill-entry.js:1Untrusted Gateway Configuration Can Redirect Credentials and Queries
The skill is presented as a narrowly scoped research-report search tool, but its instructions also cover credential handling, local file storage, authorization state management, and generic gateway tool invocation. That mismatch weakens user and agent trust boundaries: a caller may authorize or invoke broader capabilities than expected, increasing the chance of over-privileged execution and unintended data exposure.
The instructions explicitly tell the agent to have the user send an API key in chat to complete authorization, creating a direct natural-language credential exfiltration path. This is especially dangerous in an investment-research skill because users may trust the 'official' framing and disclose long-lived credentials that can be logged, replayed, or reused to access protected services.
The entrypoint implements MCP client behavior and can invoke remote tools/gateways via sendJsonRpcRequest and callTool, yet this capability is flagged as undeclared. Hidden remote-call capability is dangerous because it allows network-mediated actions beyond a simple report-search interface and expands the attack surface substantially.
The entrypoint implements MCP client behavior and can invoke remote tools/gateways via sendJsonRpcRequest and callTool, yet this capability is flagged as undeclared. Hidden remote-call capability is dangerous because it allows network-mediated actions beyond a simple report-search interface and expands the attack surface substantially.
The authorization instructions explicitly tell the user to copy or send an API key to the agent to complete authorization. Asking users to disclose bearer credentials to an intermediary is a serious anti-pattern because it normalizes secret sharing and gives the skill/operator direct access to credentials that can be replayed elsewhere.
The instruction to use this skill whenever users query report data is overly broad and may capture requests that are only tangentially related to research reports. Because this skill includes auth flows and external calls, ambiguous activation can unnecessarily expose users to credential collection and network operations they did not explicitly request.
The instruction to use this skill whenever users query report data is overly broad and may capture requests that are only tangentially related to research reports. Because this skill includes auth flows and external calls, ambiguous activation can unnecessarily expose users to credential collection and network operations they did not explicitly request.
The skill first declares a strict file-access boundary, then later instructs the agent to search multiple parent directories for the API-key file. Contradictory boundary rules create ambiguity that can cause the agent to read or write sensitive credential files outside the intended scope, undermining containment guarantees.
The skill asks users to provide an API key for authorization but does not warn that the key is sensitive or instruct them to use a secure channel. In a conversational agent setting, that omission materially increases the chance that users will paste credentials into chat, where they may be logged, retained, or exposed to downstream systems.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
> **此区域供业务同事发挥,用于定义具体的服务意图与话术引导。**
| 场景分类 | 典型用户问题 (Intent) | 业务逻辑指导 |
| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **研报搜索** | "最新宏观经济研究报告","SH600000开盘价是多少?" | 调用 `search-research-report`。 |
|
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| 场景分类 | 典型用户问题 (Intent) | 业务逻辑指导 |
| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **研报搜索** | "最新宏观经济研究报告","SH600000开盘价是多少?" | 调用 `search-research-report`。 |
|
### 问句示例
The file is primarily an authorization/token-management CLI and generic MCP caller, not a narrow research-report search implementation as described in the metadata. This mismatch is security-relevant because users and reviewers may grant trust or permissions based on the stated purpose while the code performs broader credential and network operations.
The code derives a device identifier from the local MAC address and combines it with timestamp/random data to drive authorization. Collecting hardware-derived identifiers is unnecessary for a report-search skill and creates device fingerprinting and privacy risk if logged, stored, or transmitted.
The skill writes the API key to a shared/local JSON file on disk without any meaningful warning, consent flow, or protective controls. Persisting credentials this way increases the risk of token theft from other local users, backups, logs, or adjacent tools that can read the shared path.
After successful authorization polling, the code logs the raw server response, which may contain the API key or closely related sensitive authentication material. Emitting secrets to stdout is dangerous because terminals, shell history wrappers, CI logs, and agent transcripts may retain them far beyond the intended session.
L101 states the agent must never call the native system shell and must always use node commands, but L103-L125 then provide execute_command separator rules and PowerShell-native file existence checks. That documentation directs shell usage patterns that conflict with the earlier 'must always use node' instruction.
The help text, prompts, and operational status messages are presented exclusively in Chinese throughout the CLI output. This imposes a specific language/locale on users without offering opt-in, selection, or documentation that the skill is intended only for a Chinese-language audience.
No suspicious patterns detected.