T01 · Skill Instruction Hijacking
- Location
references/core_workflow.md:49- Finding
Mandatory promotional output hijacks normal Agent responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s core trend-query purpose is coherent, but it asks for persistent credential handling, reads shell profile files, creates ongoing subscriptions, and generates HTML with notable safety weaknesses.
Review this skill before installing. Use a scoped, revocable RedFox API key, avoid letting the agent write or echo the key in shell profiles, and prefer setting it through a session-scoped secret mechanism. Do not enable daily subscription pushes unless you understand where that state is stored and how to cancel it. Treat generated HTML reports and /tmp cache files as untrusted, especially if cache files can be modified by other users or processes.
references/core_workflow.md:49Mandatory promotional output hijacks normal Agent responses
scripts/gen_xhs_html.py:575Generated reports allow HTML and JavaScript injection from API or cache data
scripts/xhs_daily_fetcher.py:641Predictable shared temporary cache permits cache poisoning and symlink attacks
scripts/xhs_daily_fetcher.py:27Credential discovery reads shell profiles and encourages plaintext global persistence
scripts/gen_xhs_html.py:307Generated reports execute third-party CDN scripts without integrity verification
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
try:
# 接口仅支持 GET(query 参数);POST 会返回系统错误
response = requests.get(REDFOX_API_BASE, params=params, headers=headers, timeout=30)
if response.status_code >= 400:
return {"fetch_time": rank_date + " 19:00", "query_type": "日榜", "category": category, "hot_list": []}
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
try:
# 接口仅支持 GET(query 参数);POST 会返回系统错误
response = requests.get(REDFOX_API_BASE, params=params, headers=headers, timeout=30)
if response.status_code >= 400:
raise Exception(f"HTTP请求失败: {response.status_code}, {response.text}")
The workflow instructs the agent to persist a user-supplied API key into shell profiles or Windows user environment and then verify it by echoing it back. For a simple trend-query skill, modifying persistent system configuration is unnecessary and expands scope from data retrieval into credential handling, increasing the chance of secret exposure, accidental reuse by other tools, and unwanted system changes.
The README explicitly says users can invoke the skill by describing needs in natural language with no command constraints. In agent environments, overly broad invocation guidance increases the chance of accidental triggering from ordinary conversation and can cause the skill to run in contexts the user did not clearly intend, including making external API calls or initiating subscriptions.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Quick Reference
| Intent | Example phrase | Result |
| ------------------------- | ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| Query today's virals | `Show me viral notes about mascara` | Auto-matches category, outputs today's breakout TOP20 + three-dimension analysis + HTML + subscription option |
| Query general hot content | `What's trending on Xiaohongshu lately?` | Uses "All" category, full four-section output |
The trigger example "What's trending on Xiaohongshu lately?" is generic conversational wording that overlaps with normal user chat. This raises the risk that the skill is activated unintentionally during broad discussion, leading to unexpected data retrieval, external requests, or follow-on actions presented as if explicitly requested.
The README advertises automatic daily subscription pushes but does not clearly disclose the persistence of notifications, how to unsubscribe, or what user state/preferences are retained. This can lead to unauthorized or unexpected ongoing engagement, especially if users trigger subscription with a simple reply and are not warned about the behavioral and privacy implications.
This is a markdown file, so vague trigger guidance applies. The text explicitly says users need not remember commands and provides broad everyday-language examples, which could overlap with normal conversation without clarifying when the skill should or should not activate.
The skill advertises capabilities that involve environment-variable access, file reads/writes, and network use, but it does not declare any explicit tool scope or permission boundaries. In agent platforms, this can lead to over-broad execution authority, making it easier for the skill to access secrets like REDFOX_API_KEY, write files, or make outbound requests without clear sandboxing or user visibility.
The example trigger phrases are broad enough that ordinary conversation about Xiaohongshu trends or related keywords could unintentionally activate the skill. Accidental activation matters here because the skill can perform network requests and file operations, potentially causing unintended API usage, data retrieval, or local artifact generation.
The invocation guidance relies on ambiguous natural-language requests rather than unambiguous commands, increasing the chance that the agent routes unrelated user queries into this skill. Because the skill includes subscription behavior, API calls, and HTML generation, misrouting can lead to unintended external actions or content generation beyond what the user expected.
The generic trigger example '最近小红书有什么热门内容' is extremely broad and overlaps with common assistant queries, making unintended invocation likely. In context, this is more concerning because the skill is designed to fetch external data and may produce follow-on actions like analysis, subscriptions, or file output once activated.
文件整体以中文为唯一指定输出与交互形式,并多处使用“必须原样输出”等强制措辞,但未看到允许用户选择其他语言或说明仅面向特定中文场景的明确限制。根据规则,未经用户选择而强制单一语言/locale 可能构成自然语言政策违规。
The skill adds a subscription/push capability beyond one-time query and analysis, enabling ongoing actions after the initial request. Persistent notifications increase the risk of unwanted autonomous behavior, surprise data access, and repeated outbound activity that users may not fully expect from a ranking lookup skill.
The trigger conditions are broad enough to overlap with casual discussion of popular content or trends, which can cause the agent to invoke the skill unexpectedly. In this skill, accidental activation matters because it may lead to external API calls, credential checks, or follow-on actions like subscription prompts.
The workflow tells the agent to perform persistent system changes and enable push-like behavior without prominent risk disclosure or explicit consent boundaries. Users are not adequately warned that credentials may persist across sessions or that subscriptions create ongoing activity, making unintended system and privacy impact more likely.
The instructions encourage the agent to help store API credentials persistently and to verify them by printing them in the shell, which can expose secrets in terminal history, chat transcripts, screenshots, or logs. In the context of a content-ranking skill, this credential handling is disproportionate and materially increases secret leakage risk.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**💡热门内容分析**
| 内容分类 | 内容特征 | 实际效果 | 参考笔记 |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望 | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**📈爆款标题分析**
| 标题类型 | 标题特征 | 标题模版 | 发布规律 | 参考标题 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式 | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动 | "你还在XX吗?" | 工作日早高峰效果最佳 | 这个方法你还在用吗? |
| 数字式 | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值 | "XX个XX技巧" | 午餐时间点击率高 | 5个快速提升XX的技巧 |
The workflow introduces HTML/PDF export and file-package generation, which exceeds basic query-and-analysis behavior and causes filesystem side effects. Even if intended for convenience, generating files creates additional attack surface around file writes, unexpected persistence, and content export beyond the user’s immediate request.
The script scans shell profile files such as ~/.zshrc and ~/.bashrc to extract REDFOX_API_KEY without explicit consent at runtime. Reading unrelated personal config files expands the data-access scope beyond what users may expect and can unintentionally harvest secrets or sensitive local configuration from a broader set of files.
The generated HTML loads executable JavaScript from third-party CDNs at page-open time. Anyone opening the report implicitly trusts those external hosts and the network path; if the CDN is compromised, blocked, or serves altered content, arbitrary script can run in the local browser context of the report viewer.
The script's user-facing description, help text, and output strings are entirely in Chinese, effectively imposing a specific language/locale on all users. The file does not offer language selection or document that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
The script reads shell startup files such as .zshrc and .bashrc to extract REDFOX_API_KEY without explicit user consent at runtime. That is a sensitive local file access pattern not necessary for a simple trend-query skill when environment variables or explicit input would suffice, and it normalizes scanning local configuration that may contain unrelated secrets.
Accessing shell rc/profile files to obtain credentials is a privacy-sensitive behavior because those files may contain other secrets, tokens, aliases, or personal configuration. Even though the current code only searches for a specific export line, this local secret-discovery behavior is broader than the skill's stated purpose and occurs without a prominent warning or opt-in.
Detected: suspicious.exposed_secret_literal