T01 · Skill Instruction Hijacking
- Location
scripts/format.js:91- Finding
Forced Third-Party Link Injection Through Mandatory Skill Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches a hot-news briefing purpose, but it automatically sends generated content to Feishu and forces unreviewed third-party links and remote-supplied Markdown into that message.
Review this skill before installing. It does not appear to steal secrets or persist on the system, but it is designed to post generated reports to Feishu and includes fixed external footer links plus unsanitized links from remote hot-list sources. Use it only where Feishu posting is intended, and prefer a version that previews the exact message, validates links, and asks for approval before sending.
scripts/format.js:91Forced Third-Party Link Injection Through Mandatory Skill Instructions
scripts/format.js:85Untrusted Remote Titles and URLs Are Embedded in Markdown Without Validation
The skill’s declared purpose is to fetch and summarize hot topics, but the instructions also entail undeclared external network access, local file creation, and downstream transmission behavior not clearly surfaced in the metadata. This mismatch reduces user visibility into what the skill actually does and can lead to unintended data handling or execution of broader actions than the user expects.
Referenced artifact was not completely inspected
1. 抓取数据:`node ./scripts/index.js`
Referenced artifact was not completely inspected
2. 读取并聚类:`node ./scripts/format.js`
The skill instructs sending generated hot-topic output to Feishu, which is an external transmission step, but does not require explicit user consent or provide a warning before exfiltrating content. Even if the data appears public, automatic outbound delivery can leak sensitive context such as user prompts, derived summaries, or organizational usage patterns.
The skill description and operational instructions are entirely in Chinese and constrain the model to a fixed output process without indicating that users may choose another language. This can violate language/locale policy when no user opt-in or documented locale limitation is provided.
The file contains user-facing natural language in Chinese in its header comments and generated markdown output, such as the title and platform labels. Under the policy, forcing a specific language without user opt-in can be a locale policy violation unless the restriction is clearly documented and justified, which is not present here.
The HTTP request headers hard-code Accept-Language: zh-CN,zh;q=0.9, which imposes a specific locale preference in all requests. This is a natural-language/locale policy concern because the skill does not offer user opt-in or explain why a Chinese locale is required.
No suspicious patterns detected.