T01 · Skill Instruction Hijacking
- Location
SKILL.md:2- Finding
Broad Skill Routing and Untrusted Remote Output Reproduction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This job-listing skill should be reviewed because it broadly triggers on work or money requests and sends the full user message to an external test API.
Install only if you are comfortable having job-search or earning-money requests sent to this external 快结荐 test API. Avoid entering resumes, phone numbers, precise addresses, identity details, or private employment information unless the publisher adds clear consent, data minimization, and privacy documentation.
SKILL.md:2Broad Skill Routing and Untrusted Remote Output Reproduction
scripts/call-wx-skill.py:11Unconsented Transmission of Complete User Messages to a Third-Party Test API
The skill explicitly sends the user's message content to an external backend API without any user-facing disclosure or consent step. Users may include sensitive personal, employment, financial, or location details in job-seeking prompts, so silent transmission to a third party creates a clear privacy and data-sharing vulnerability.
The skill instructs use of a networked backend API but does not declare any explicit tool scope or permissions boundary. This creates a governance and review gap: the agent may invoke external network access without clear policy constraints, making data exfiltration and unintended outbound requests harder to audit and control.
The trigger phrases are broad enough to match ordinary requests about work, money, or help, which can cause the skill to activate in contexts the user did not intend. Because the skill forwards user content to a third-party API, accidental invocation also becomes accidental data disclosure to an external service.
The skill is presented entirely in Chinese and oriented to a Chinese platform without offering any language choice or opt-in behavior. Because the instructions and routing are language-specific with no explicit user selection, this may violate language/locale policy requirements for offering choice unless the locale restriction is documented and justified.
The routing rules use underspecified examples such as '赚钱' and '求职' that are semantically broad and likely to over-trigger. In this skill's context, over-triggering is more dangerous because the workflow mandates transmitting the user's raw message to a backend API, so ambiguity directly increases privacy and consent risk.
The script sends arbitrary user-provided content directly to an external API endpoint with no disclosure, consent check, redaction, or minimization. In a job-seeking skill, users may submit sensitive personal or employment-related information, so silent transmission to a remote service creates a real privacy and data-handling risk even if the network call is the skill's intended function.
No suspicious patterns detected.