T01 · Skill Instruction Hijacking
- Location
SKILL.md:117- Finding
Unauthenticated Auto-Query Trigger Allows Instruction Hijacking and Unauthorized Report Forwarding
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its DeepSOP sales-assistant purpose, but it handles sensitive customer and communication data with under-scoped automatic reporting and unsafe shell-oriented instructions.
Review before installing in any workspace with real customer data. Only use it where DeepSOP API access and report delivery destinations are tightly controlled, and require fixes for authenticated cron callbacks, fixed/authorized message targets, safe non-shell argument handling, stdin/file-based JSON transfer, and PII minimization or masking in chat and exported reports.
SKILL.md:117Unauthenticated Auto-Query Trigger Allows Instruction Hijacking and Unauthorized Report Forwarding
SKILL.md:1823Shell Command Injection Through Interpolated Callback Fields and API Response JSON
scripts/format_customers.py:94Spreadsheet Formula Injection in Generated Customer and Communication Reports
声明描述的是一个面向销售任务与外呼场景管理的自动化技能,核心能力应包括:解析用户意图、构造任务参数、通过指定脚本向 deepsop 提交任务、查询任务结果并推送。实际代码却只是一个离线格式化脚本:从命令行接收 JSON 和输出路径,解析 describeJobJson 中的通话详情,并使用 openpyxl 生成带样式的 xlsx 报表。代码中没有网络请求、没有 deepsop 接口、没有提交/审核逻辑、没有 cron 回调处理,也没有调用声明中要求的 submit_task.py 或 submit_script_review.py。其主要用途与声明的主要用途明显不同,因此属于明显不匹配。
声明描述的是一个面向销售任务/场景审核的编排型技能,核心能力应是解析指令、调用 deepsop API、提交任务、轮询查询与推送结果,并且依赖特定提交脚本。实际代码仅是一个数据格式化工具,输入 JSON、输出 xlsx,不涉及任何 API 调用、任务提交、审核、定时触发或用户指令处理。该代码的主要用途与声明的主要用途明显不同,且实现了声明中未提及的导出 Excel 功能,因此属于明显不匹配。
代码的实际功能与声明的核心目的明显不一致。声明描述的是一个面向销售任务和外呼场景的自动化技能,重点在调用 DeepSOP 接口提交任务、审核场景并查询结果;而给出的代码块只是一个数据导出工具,读取命令行参数中的 JSON,生成邮件数据报表并写入 xlsx 文件。它既没有使用 DEEPSOP_API_KEY,也没有任何 HTTP/API 调用、任务编排、cron 回调处理、submit_task.py 或 submit_script_review.py 相关行为。因此这是明显的 description-behavior mismatch。
声明描述的核心能力是:根据用户销售/客户挖掘/外呼场景指令,调用 DeepSOP 平台接口提交任务、审核场景、等待查询并推送结果,还要求走特定 submit 脚本。实际代码完全没有这些行为。它只接收命令行参数中的 JSON 字符串和输出路径,解析短信结果列表,并使用 openpyxl 生成 Excel 文件。代码涉及的数据域是“Lisa 短信任务 getSmsResultList 返回的 JSON”,而不是客户挖掘、销售任务、电话场景或 DeepSOP。其资源访问模式也不同:仅本地文件写入,无网络请求、无 API key 使用、无定时触发逻辑、无提交/查询工作流。因此该代码块与声明用途存在明显且实质性的描述-行为不匹配。
声明描述的核心能力是 DeepSOP 销售任务/外呼场景的提交、审核、查询与推送,且依赖特定脚本与平台接口。提供的代码块却是完全不同领域的短信模板变量校验工具,关注时间、姓名、单位名、地址、验证码、邮箱等字段格式限制。该代码没有任何 DeepSOP API 调用、任务提交、轮询查询、cron 处理、自然语言解析或场景创建/审核逻辑。因此这不是对声明功能的支持性细节,而是一个与声明主用途明显不同的独立能力,构成实质性描述-行为不匹配。
The cron payload embeds task identifiers, customer-pool references, employee participation, chat destination IDs, and detailed instructions to transmit generated reports and summaries into external messaging channels. Storing and replaying this much operational and customer-linked context in plain text increases the blast radius of misdelivery, log leakage, job inspection, or unauthorized access to scheduled payloads.
The AiWa result preview explicitly instructs the agent to reveal personal and contact information in chat, including names, positions, company names, email addresses, phone numbers, and social handles. That is unnecessary broad disclosure of customer PII and business contact data, especially in chat contexts where access control, retention, and audience scope may be unclear.
The phone-call workflow directs disclosure of detailed call records, phone numbers, contact identities, and conversation content summaries. Call transcripts and interaction metadata are highly sensitive and may contain personal data, commercial information, or regulated communications that should not be broadly echoed into chat or pushed automatically.
The email and SMS result steps require exposing recipient email addresses, phone numbers, message subjects/content, delivery status, and timestamps in chat and exported files. This is a direct risk of leaking personal data, campaign content, and communication metadata to unintended viewers or systems, especially when combined with automatic push behavior.
The document first mandates script-only submission to preserve UTF-8 safety and validation, but later tells implementers to use curl for HTTP requests. Contradictory security guidance causes operators or agents to bypass the validated wrappers, which can disable input validation and increase the chance of malformed or unsafe direct requests.
The usage instructions tell users to 'directly speak your needs' and provide only Chinese example utterances, while the document as a whole is written primarily in Chinese. This creates a natural-language expectation that the skill operates in Chinese only, but the README does not offer users a language/locale choice or justify a locale restriction.
The skill describes capabilities that access environment secrets, read/write files, perform network requests, and execute shell commands, but it declares no explicit tool scope or permission boundaries. That increases the risk of overbroad execution and makes accidental or unauthorized use of sensitive capabilities harder to constrain or audit.
The phrase 'instructions related to customer mining and sales tasks' lacks clear boundaries, making invocation ambiguous. In a skill that can process customer data and trigger external submissions, overbroad matching can lead to accidental task creation or disclosure from casual user prompts.
The phrase 'instructions related to customer mining and sales tasks' lacks clear boundaries, making invocation ambiguous. In a skill that can process customer data and trigger external submissions, overbroad matching can lead to accidental task creation or disclosure from casual user prompts.
The skill is designed to handle API keys, user profile data, customer records, contact details, and outbound messaging, but it does not present clear upfront notice about collection, use, external transmission, or retention of that data. This weakens user consent and increases privacy/compliance risk, especially because data may be pushed to external channels and files may be generated on disk.
L0166 规定只要提及国家或地区且与中国无关联就返回“英文”,否则返回“中文”,这是基于地域的强制语言策略,而不是让用户选择语言。该规则会在未获用户明确偏好时替用户决定语言/locale,符合语言与区域策略方面的自然语言政策风险。
The main flow explicitly allows Frank/Fran/Lisa to run without AiWa by entering Step 1.6, where the user supplies customer sources via xlsx upload or company search. The error-handling bullet instead says such tasks should be terminated and the user told to add customer mining requirements, which is the opposite of the intended behavior.
In Step 3, when no PUBLISHED Fran scene exists, the documented behavior is to offer the user an immediate creation path via Step 1.7 or let them cancel. The error-handling section instead instructs outright termination and sending the user to the website, contradicting the interactive fallback flow defined earlier.
The manifest describes this skill as analyzing sales instructions, submitting DeepSOP tasks, querying results, and creating/reviewing outbound-call scenarios. This file instead converts call-result JSON into an XLSX spreadsheet, which is a materially different user-visible behavior not mentioned in the manifest description.
The script writes sensitive call records to an Excel file, including contact names, phone numbers, company names, timestamps, and conversation summaries, without any built-in minimization, masking, consent prompt, or retention control. In this skill context, the data is sales/call-center information and may contain personal data and conversation content, so exporting it to a local file increases the risk of privacy leakage, secondary sharing, and non-compliant storage.
The natural-language docstring presents the script description, usage, and output entirely in Chinese, with no indication that other languages are supported or that Chinese is a required locale for a region-specific tool. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation.
This code file saves processed email task data, including recipient addresses, phone numbers, and LinkedIn details, to disk via wb.save(output_path). While the module docstring states that it outputs an xlsx file, there is no runtime confirmation or explicit user-facing warning that potentially sensitive contact data will be written to the specified path.
This Python file contains natural-language documentation and runtime messages exclusively in Chinese, including usage instructions and status summaries. That creates a locale policy issue if the skill is used in broader contexts, because it imposes a specific language without offering the user a choice or documenting that the skill is region/language-specific.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + 双重 pre-flight 校验 + HTTP 提交。
为什么需要这个脚本(替代 LLM 直接写 curl):
- LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
- 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + 双重 pre-flight 校验 + HTTP 提交。
为什么需要这个脚本(替代 LLM 直接写 curl):
- LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
- 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,
Detected: suspicious.exposed_secret_literal