T01 · Skill Instruction Hijacking
- Location
SKILL.md:41- Finding
Mandatory Commercial Response Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This transcript-extraction skill is purpose-related, but it asks users to paste an API key into chat and requires running an unpinned npm package from the live registry.
Review before installing. Use this only if you are comfortable with the zimujun npm package and service. Do not paste `ZMJ_API_KEY` into chat; configure it locally through a secure environment or secret manager. Prefer a version-pinned package or a reviewed local installation instead of `zimujun@latest`.
SKILL.md:41Mandatory Commercial Response Injection
SKILL.md:19Automatic Execution of an Unpinned Latest npm Package
SKILL.md:73API Key Solicitation Through the Conversation
The text explicitly offers: 'send me the key and I will help set the environment variable,' which normalizes direct secret collection by the agent. In an LLM-agent setting this is dangerous because secrets may be stored in transcripts, mishandled by tools, exposed in logs, or reused beyond the user's expectation.
The skill executes npx --yes zimujun@latest, which fetches and runs the newest package version at invocation time rather than a reviewed, pinned release. This creates a supply-chain risk: if the npm package is compromised or a breaking/malicious update is published, the agent would execute unreviewed code automatically.
This second occurrence repeats the same unsafe pattern of invoking npx --yes zimujun@latest, causing runtime retrieval and execution of whatever code is currently published under that package. In the context of an agent skill, that is especially risky because the tool may be invoked on user request with little friction.
The skill tells the user they can send the API key directly to the agent, but it does not include a clear warning about the sensitivity of that credential or the risks of sharing secrets in chat. This can lead users to disclose reusable credentials into channels that may be logged, retained, or exposed to downstream tooling.
No suspicious patterns detected.