T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Mandatory Skill Routing Overrides Agent Tool Selection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This ProcessOn diagram skill has a coherent diagram-generation purpose, but it asks for broad automatic routing, remote authentication, mutable updates, token storage, and automatic package installation with insufficient containment.
Install only if you are comfortable sending diagram prompts and related context to ProcessOn, storing a local bearer token, and allowing npm-based dependency setup. Prefer a version pinned to a reviewed commit, avoid forced global updates, and do not use this with secrets, proprietary architecture details, or regulated data unless your organization approves ProcessOn for that use.
SKILL.md:3Mandatory Skill Routing Overrides Agent Tool Selection
SKILL.md:19Mutable Remote Skill Update Can Replace Reviewed Code and Instructions
setup.mjs:75Automatic npm Execution and Global Dependency Installation
setup.mjs:23Environment-Controlled MCP Endpoint Can Receive the Stored Bearer Token
setup.mjs:487Public Hard-Coded Shared Secret and Unauthenticated Authorization-Code Construction
The skill declares a mandatory trigger for broad and ambiguous phrases like 'draw', 'generate chart', and 'visualize', and explicitly tells the agent not to skip the skill. This can hijack a wide range of user requests, override safer/native handling paths, and unnecessarily route benign prompts into a workflow that performs network access, auth, and command execution.
The invocation rules include a catch-all requirement for any request containing generic drawing or visualization language, making the skill eligible far beyond its least-privilege purpose. In context, this is especially risky because the skill couples broad auto-invocation with remote auth, update logic, and shell-based orchestration, amplifying the blast radius of misrouting.
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
Referenced artifact was not completely inspected
node ./setup.mjs processon_check_and_start_auth
checkMcporter() will run npm install -g mcporter@... on the host when the tool is absent. Global package installation modifies the host environment and executes install scripts with the user's privileges, which is an unjustified and high-risk capability for a skill whose advertised function is only diagram generation.
The README instructs users to install and run a remote skill via npx skills add from a GitHub repository without pinning to a specific immutable version, tag, or commit. This creates a supply-chain risk: repository changes or compromised upstream dependencies could cause users to fetch and trust different code than was originally reviewed.
The update command uses npx skills add ... --force -g -y without pinning a version, which increases supply-chain exposure by forcing replacement with whatever content is currently served from the remote repository. If the repo or its delivery path is compromised, users may silently install altered skill behavior.
The README states that the skill uses browser-based authorization and returns generation outputs, but it does not clearly warn that users are redirected to an external ProcessOn service and may transmit prompts, diagrams, or code context to that third party. This omission can lead users to disclose sensitive business logic or source code without informed consent, especially because the skill explicitly supports natural language and code context.
The skill invokes shell commands, accesses environment-capable runtime components, performs network requests, and manages OAuth/token state, yet it declares no explicit tool scope or permission boundary. This creates a mismatch between what the skill appears to require and what it actually does, increasing the chance of over-privileged execution and reducing reviewability.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal