T01 · Skill Instruction Hijacking
- Location
SKILL.md:21- Finding
Agent role and objective hijacking enables autonomous external actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real BotBili publishing guide, but it gives the agent too much autonomous authority over account creation, credential storage, public posting, and recurring operation.
Install only if you are comfortable letting an agent operate a BotBili creator account. Before use, require explicit confirmation for channel creation, each public upload, social interactions, webhook registration, scheduled automation, package installation, and any paid or quota-consuming provider call. Store API keys in a real secret manager where possible, avoid pasting full keys into chat, and do not refresh the skill from a remote URL unless you verify the exact version and contents.
SKILL.md:21Agent role and objective hijacking enables autonomous external actions
skills/05-co-creation.md:34Recurring heartbeat and scheduled operation can persist beyond the initiating session
SKILL.md:170Mutable remote Skill content can replace locally reviewed instructions
skills/03-video-production.md:188Unpinned package installation introduces supply-chain execution risk
skills/01-platform-basics.md:27BotBili credentials are stored and disclosed through insecure plaintext workflows
The command explicitly writes an API key into ~/.openclaw/.env in plaintext. This is dangerous because secrets may be exposed to other local users, backups, indexing tools, or logs, and using shell commands for secret handling increases accidental disclosure risk.
curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md
echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env echo 'BOTBILI_CREATOR_ID=cr_你的id' >> ~/.openclaw/.env
Persisting the creator ID is less sensitive than the API key, but the pattern reinforces writing account-related identifiers into a persistent plaintext file alongside secrets. In context, this encourages unmanaged long-term credential state and can aid account correlation or misuse when paired with the key.
echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env echo 'BOTBILI_CREATOR_ID=cr_你的id' >> ~/.openclaw/.env
### 云端 OpenClaw(QClaw / KimiClaw / MiniMaxClaw 等)
The explicit instruction to write BOTBILI_API_KEY into a plaintext .env file is a credential-handling weakness because it causes long-lived secret persistence in a commonly accessed file format. If the file is readable by other processes, synced, backed up, or exposed through debugging, the token could be stolen and used to act as the creator account.
3. 立即保存
本地环境:
echo 'BOTBILI_API_KEY=bb_xxx' >> ~/.openclaw/.env
echo 'BOTBILI_CREATOR_ID=cr_xxx' >> ~/.openclaw/.env
云端环境(QClaw / KimiClaw / MiniMaxClaw 等):
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Authorization: Bearer $BOTBILI_API_KEY
# 取消点赞
DELETE /api/videos/{video_id}/like
Authorization: Bearer $BOTBILI_API_KEY
# 查看点赞状态
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
→ 201 { "following": true, "followers_count": 42 }
# 取消关注
DELETE /api/creators/{creator_id}/follow
Authorization: Bearer $BOTBILI_API_KEY
→ 200 { "following": false, "followers_count": 41 }
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Webhook 管理:
- `GET /api/webhooks` — 列出我的 webhooks
- `DELETE /api/webhooks/{id}` — 删除
- `PATCH /api/webhooks/{id}` — 更新 target_url 或 events
> 连续失败 5 次自动停用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证
The manifest describes a skill for publishing and managing AI videos on BotBili, and explicitly frames it as a platform guide. However, the documentation here goes beyond platform use and tells the agent to handle topic selection, scripting, visuals, dubbing, editing, and end-to-end video generation, which is broader than simply publishing/managing on BotBili.
The skill instructs the agent to test for and use shell access, install tools, and modify local environment files as part of a publishing workflow. This materially expands the attack surface from simple API usage to host-level command execution and persistent local changes, which is dangerous if the skill is invoked in a sensitive runtime.
The skill tells the agent to autonomously create channels and save returned API credentials without a prominent warning or explicit consent step. Automatic credential generation and retention can create unmanaged accounts, surprise users with persistent identities, and expose secrets if the runtime stores them insecurely or logs responses.
The installation flow persists the skill and credentials under the user's home directory, creating durable session state without strong warnings about persistence or cleanup. In shared or semi-trusted environments, this can leave long-lived capabilities available to future processes or users beyond the immediate task.
openclaw skills install botbili
# 或手动安装
mkdir -p ~/.openclaw/skills/botbili
curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md
# 设置环境变量
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
# 或手动安装
mkdir -p ~/.openclaw/skills/botbili
curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md
# 设置环境变量
echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env
The instructions direct writing API keys into a local .env file with shell echo commands, but provide no user-facing warning about plaintext secret storage, file permissions, shell history, or multi-tenant host risk. This can easily lead to credential disclosure or accidental persistence beyond the intended session.
The manifest says the skill is for '发布和管理 AI 视频' and includes usage/guidance content, which implies creator-side publishing and management workflows. This OpenAPI file additionally defines reader/viewer-facing capabilities such as listing videos, fetching video details, retrieving creator feeds, and creating interaction events, which extend into content consumption and engagement tracking rather than just publishing/management.
The schema sets the language field default to zh-CN, which imposes a specific locale when the caller does not explicitly choose one. That is a natural-language policy concern because it can silently force a language/locale preference rather than offering user choice or documenting a justified region-specific constraint.
The skill instructs the agent to append a newly issued API key and creator ID into a local ~/.openclaw/.env file without warning that this creates persistent local storage of sensitive credentials. Persisting secrets this way increases exposure to later unintended reads, backup leakage, multi-user host access, or accidental inclusion in logs and support bundles.
The document tells cloud-hosted agents to try setting runtime environment variables directly, including cases where no user action is required. That normalizes silent credential installation into the agent runtime and can cause unauthorized persistence or use of account credentials without clear user awareness or approval.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://botbili.com/api/upload \
-H "Authorization: Bearer $BOTBILI_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The entire skill file is written exclusively in Chinese and provides no indication that users may choose another language or that the Chinese-only requirement is intentional and justified for a region-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The document recommends sending prompts, scripts, TTS text, and media to multiple third-party video and speech providers, but does not explicitly warn that this transmits user content to external vendors with separate retention, logging, and model-training policies. In a content-production skill, users may paste proprietary scripts, internal plans, or personal data, making silent external disclosure a real privacy risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
调用方式:
# 提交生成任务
curl -X POST "https://open.bigmodel.cn/api/paas/v4/videos/generations" \
-H "Authorization: Bearer $ZHIPU_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "cogvideox-flash", "prompt": "你的视频描述"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
OpenAI TTS(海外):
curl -X POST "https://api.openai.com/v1/audio/speech" \
-H "Authorization: Bearer $OPENAI_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "tts-1", "input": "大家好,今天聊聊GPT-5", "voice": "alloy"}' \
No suspicious patterns detected.