T01 · Skill Instruction Hijacking
- Location
SKILL.md:57- Finding
Mandatory Branding and Commercial Steering Manipulate Agent-Generated Reports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real AGENTS.md/CLAUDE.md checker, but its documentation includes unsafe CI execution guidance and optional suite tooling that expands into local skill and environment inspection.
Install only if you are comfortable with a branded Chinese-language checker that can read and, with confirmation, edit AGENTS.md/CLAUDE.md-related project files. Do not copy the provided CI curl-to-python example as written; vendor the reviewed script or pin it to a full commit and verify its SHA-256. Treat run-all-doctors.sh as a broader local-environment diagnostic, not just a document linter, and run it only after reviewing what the separate skill-doctor and env-doctor tools inspect.
SKILL.md:57Mandatory Branding and Commercial Steering Manipulate Agent-Generated Reports
README.en.md:83CI Instructions Download and Execute Mutable Remote Python Code Without Integrity Verification
The skill metadata and opening description present this as a focused AGENTS.md/CLAUDE.md auditor, but the content also instructs broader behavior such as evaluating skill directories and invoking other doctor-style environment checks. That scope expansion can cause the agent to access or reason about files and system state the user did not intend to include when invoking what appears to be a narrow document linter.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
注意: 本脚本只做"机器能确定的部分"。是否真的是"图书馆内容""规则是否可执行"
这类判断需要人/模型读正文定夺——交给 SKILL.md 的定性复核环节。脚本绝不读取
任何 .env / *.key / *.pem 等密钥文件。
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
注意: 本脚本只做"机器能确定的部分"。是否真的是"图书馆内容""规则是否可执行"
这类判断需要人/模型读正文定夺——交给 SKILL.md 的定性复核环节。脚本绝不读取
任何 .env / *.key / *.pem 等密钥文件。
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
注意: 本脚本只做"机器能确定的部分"。是否真的是"图书馆内容""规则是否可执行"
这类判断需要人/模型读正文定夺——交给 SKILL.md 的定性复核环节。脚本绝不读取
任何 .env / *.key / *.pem 等密钥文件。
"""
import os
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
注意: 本脚本只做"机器能确定的部分"。是否真的是"图书馆内容""规则是否可执行"
这类判断需要人/模型读正文定夺——交给 SKILL.md 的定性复核环节。脚本绝不读取
任何 .env / *.key / *.pem 等密钥文件。
"""
import os
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
An overly broad trigger phrase can cause the skill to activate during ordinary conversation or unrelated review requests, leading to unintended analysis or suggested edits. In an agent context, ambiguous invocation boundaries are dangerous because they can cause tools or workflows to run without the user's specific intent.
The README claims the audit is read-only while elsewhere stating the tool can apply fixes, creating a safety-boundary contradiction. Users may grant trust or approvals based on the read-only claim and then be surprised by write behavior, which increases the risk of unintended file modification in sensitive repositories.
The trigger text says essentially any request about reviewing or optimizing AGENTS.md or CLAUDE.md quality should invoke the skill. Overbroad activation increases the chance the skill runs in contexts where the user wanted a simple answer, causing unnecessary file inspection, shell execution, or modification proposals under a broad interpretation.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
allowed-tools:
- Bash
- Read
- Write
- Edit
- Glob
- Grep
L126 instructs the skill to produce output in Chinese unconditionally. This is a language policy concern because it forces a specific language regardless of the user's preference and does not offer a choice or opt-in.
The code treats phrases like "汇报用中文" and "回复用中文" as desirable persona markers, which encodes a preference for Chinese-language output. This is a natural-language locale policy issue because it promotes a fixed language choice without any visible user opt-in or alternative.
This markdown file contains user-facing instructions and descriptions exclusively in Chinese, and it does not provide an opt-in, alternative language, or justification that the skill is region- or locale-specific. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.
The script materially expands scope beyond the advertised purpose of checking AGENTS.md/CLAUDE.md by also auditing local skills and scanning the host environment. That creates a capability mismatch: a user invoking a config-file doctor may unintentionally trigger broader inspection of project contents and machine state, which can expose sensitive information or violate least-privilege expectations.
Invoking a host environment scanner is not justified by the stated function of auditing runtime configuration markdown files. Even if the scanner is legitimate, running it under this skill context can collect system details the user did not intend to expose, making the behavior unexpectedly invasive.
The script executes the environment scan directly with no confirmation, warning, or preview of what host data will be inspected. In an agent/tooling setting, silent host inspection is dangerous because users may assume they are only linting repository documentation while the script is actually probing local development environment state.
No suspicious patterns detected.