T01 · Skill Instruction Hijacking
- Location
SKILL.md:33- Finding
Mandatory Unrelated Promotional Output Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent GEO audit purpose, but it needs review because it handles CMS write credentials and documents a way to bypass host validation for CMS mutations.
Install only if you are comfortable reviewing the MCP write-back flow first. Prefer read-only audit mode, avoid storing CMS Bearer tokens in plaintext config, do not use the documented direct JSON-RPC validation bypass, and run the crawler only against sites you intend to audit from a network environment that cannot reach sensitive internal services.
SKILL.md:33Mandatory Unrelated Promotional Output Hijacks Agent Responses
references/mcp-tools.md:110Instructions Explicitly Bypass Host Tool Validation for CMS Writes
scripts/geo_audit.py:450Unrestricted URL Fetching Enables Server-Side Request Forgery
references/mcp-tools.md:3CMS Bearer Tokens Are Persisted in Plaintext Configuration
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The guidance explicitly allows synthetic aggregateRating values (ratingValue 4.5–5.0, reviewCount 80–100) as a placeholder, even though ratings are a trust signal that search engines and downstream AI systems may ingest as factual metadata. This creates a direct path for deceptive structured data, and the later disclaimer that it should not be shown on-page does not remove the risk because crawlers can still consume and surface it.
The document contains contradictory rules: it declares a global red line against fabricated ratings and other factual fields, but elsewhere authorizes fabricated rating placeholders. Such inconsistency is dangerous in an automation-oriented skill because implementers or agents may follow the permissive instruction and produce deceptive schema that undermines content integrity and could trigger search-engine penalties or mislead AI summaries.
The skill instructs collection and storage of a user-supplied MCP endpoint and bearer token in a user-level config file under ~/.workbuddy/mcp.json. Accessing and modifying persistent credential configuration expands the blast radius beyond the current session, and a malicious or compromised skill could exfiltrate, reuse, or redirect credentials to attacker-controlled endpoints.
# CMS MCP 写回映射(mcp-tools)
本技能在「目标站为支持 MCP 的 CMS 且需执行修改」时,经 MCP 回写 GEO 优化内容。MCP 地址与 Bearer Token 由用户提供(写入用户级 `~/.workbuddy/mcp.json` 的 `mcpServers.<name>.url` 与 `mcpServers.<name>.headers.Authorization`,或由会话提供的 MCP 服务注入)。
## 向用户索取 MCP 地址与访问 Token(必读,写操作前必做)
The workflow repeats instructions to write the MCP URL and Authorization header into mcp.json as a 'single source of truth.' Persisting live bearer credentials in a general user config file makes credential theft or unintended reuse more likely, especially because the same file is later consumed by direct backend tooling.
### 拿到后如何处理
1. **写入配置(单一数据源)**:把地址写入 `mcp.json` 的 `mcpServers.<name>.url`,Token 写入 `mcpServers.<name>.headers.Authorization`(`Authorization: Bearer <token>`)。若宿主已托管该 MCP 服务,则直接复用会话内已连接的同名服务,无需重复索取。
2. **验证连通性(必须,写前第一动作)**:调用 `test` 工具进行连通性检测——
- **通过**:服务可达、鉴权通过,继续用 `tools/list` 确认 `list_page`、`save_ai_page`、FAQ 工具等可用。
- **失败**:立即停下,向用户反馈「地址或 Token 无效 / 无权限」,**不得猜测重试或降级到伪造数据**。
Although the text says the token should not be echoed or logged, it still endorses reading the token from mcp.json for a direct backend script. This normalizes local file-based secret access by auxiliary tooling, which weakens compartmentalization and makes accidental leakage, misuse, or bypass of normal access controls more likely.
### 安全红线
- Token 仅由 MCP 客户端放入 `Authorization: Bearer`,**不回显、不落文件(除 `mcp.json` 受信位置外)、不出现在任何报告/日志/截图**。
- 未拿到 Token 前,**只做只读分析,不调用任何写工具**(`save_ai_page` / FAQ 写入工具等)。
- 直连后端脚本(见文末)从 `mcp.json` 读 Token,保持单一数据源;仅可信本地环境使用。
## 前置要求(写操作前必做)
1. 已按上文「向用户索取 MCP 地址与访问 Token」完成索取、写入与连通性验证。
This line combines two risky behaviors: reading a bearer token from mcp.json and using it to perform raw JSON-RPC calls that bypass host validation. In context, that turns persistent credential access into a practical mechanism for invoking sensitive write/delete tools outside the intended security boundary.
JSON-LD 中的网址、Logo、图片地址必须是完整 URL(优先 `FnGetHost(1)` 拼接或 `FnGetCurrentUrl()`)。
## 直连后端提示
若宿主 `DeferExecuteTool` 的本地 ajv 校验因 `oneOf`/`coerceTypes` 误拦截带 `pageId` 的写工具(如 `save_ai_page`、`del_page`),可改用直连后端脚本(从 `mcp.json` 读 Token,POST JSON-RPC:`initialize` → `notifications/initialized` → `tools/call`)绕过宿主校验。仅在可信本地环境使用,且仍须遵守上述数据标签与真实数据红线。
## 写后验证
回写后:① 在 CMS 预览确认页面正常;② 重新 `analyze`(或 `validate` 对比基线)确认 GEO Score 提升、schema 类型出现、无模板绑定破坏。
The skill explicitly instructs the agent to perform network crawling, local file reads/writes, and page modification workflows, but it does not declare any tool scope or allowed-tools boundaries. This creates an authorization ambiguity where an agent runtime may over-grant capabilities, increasing the chance of unintended network access, filesystem access, or write actions against external systems.
The markdown states that the skill is limited to Twig version 1.3 and instructs the agent to write with that version in mind. This is a natural-language locale/technology constraint presented as mandatory, but the file does not offer user choice or explain why this fixed version is required for all users.
The document states that industry detection is based on '12 个中文行业词库', which hard-codes a Chinese-language taxonomy rather than offering multilingual handling or user opt-in. This creates a language/locale policy concern because the skill behavior is constrained to Chinese without documenting a justified regional limitation for all use cases.
Suspicious Unicode normalization or mixed-script content
The entire skill guidance, prompts, and operational instructions are written in Chinese, including the copy-paste user-facing wording. There is no indication that users may choose another language or that the Chinese-only constraint is required for a documented region-specific purpose, which can violate a language/locale choice policy.
The document explicitly instructs operators to bypass host-side MCP tool validation by calling the backend JSON-RPC interface directly and reusing the bearer token from mcp.json. Even though it says 'only in a trusted local environment,' this undermines security controls enforced by the host, increases the chance of unsafe tool invocation, and can enable unauthorized or insufficiently validated write/delete operations if the skill or operator is mistaken or compromised.
The request headers hard-code Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, causing the crawler to preferentially retrieve Chinese-localized content regardless of the user's locale. This is a natural-language locale policy concern because the tool imposes a specific language setting without offering opt-in, opt-out, or justification that the tool is region-specific.
The crawl routine fetches remote URLs, saves returned HTML pages to disk, and writes a manifest file, but this function and its CLI path do not include a confirmation prompt or clear user-facing warning about those side effects. Although the script's purpose implies crawling, the code itself does not disclose that it will persist site content locally in the chosen output directory.
No suspicious patterns detected.