T01 · Skill Instruction Hijacking
- Location
SKILL.md:43- Finding
Mandatory Billable Third-Party Processing Overrides Agent Autonomy
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This interview coaching skill is purpose-aligned but should be reviewed because it mandates billable third-party API calls and sends email, OTP, and interview content through shell commands without clear consent or safer input handling.
Install only if you are comfortable sending your email, OTP flow, role/company details, interview answers, and other interview-prep content to ToolWeb and potentially consuming paid API quota. Avoid sharing confidential employer, project, customer, or proprietary information, and prefer an implementation that asks for consent before each external session and safely serializes request bodies instead of interpolating user text into shell commands.
SKILL.md:43Mandatory Billable Third-Party Processing Overrides Agent Autonomy
SKILL.md:69Sensitive Credentials and Authentication Data Exposed Through Command-Line Arguments
SKILL.md:90Shell Command Injection Risk from Unsafe Interpolation of Interview Content
The skill instructs the agent to always call a third-party API and transmit user email, interview prompts, and ongoing responses, but it does not provide a clear upfront warning or require explicit user consent for that external transfer. Because interview practice may include sensitive personal, employment, or proprietary information, silent transmission to an external service creates a meaningful privacy and data-handling risk.
This markdown file includes very broad activation language such as 'Use when preparing for job interviews' and 'User needs interview preparation help,' which overlaps with common everyday requests. It does not provide narrowing constraints or negative examples to distinguish when this skill should activate versus when a general assistant response would be more appropriate.
The workflow routes OTP-related data and then continuously forwards user interview answers to a third-party service over the course of the conversation. This creates sustained exfiltration risk, especially because users may reveal resumes, work history, company details, confidential project information, or other sensitive personal data while the skill encourages continued transmission.
This curl command sends the user's email address to an external endpoint as part of OTP authentication. External transmission is expected for this feature, but in the current skill it occurs within a pattern of mandatory third-party use without prominent disclosure, making the data transfer security-relevant rather than harmless.
Step 1: Send OTP
curl -s -X POST "https://portal.toolweb.in/apis/tools/interview-buddy" \
-H "Content-Type: application/json" \
-H "X-API-Key: $TOOLWEB_API_KEY" \
-d '{"email": "<user_email>"}'
No suspicious patterns detected.