T01 · Skill Instruction Hijacking
- Location
SKILL.md:231- Finding
Automatic Disclosure of User Statements and Inferred Intent to a Feedback Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does perform 1688 image search, but it also adds sensitive account, payment, upload, local-retention, and automatic feedback behavior that needs review before installation.
Install only if you are comfortable giving this skill LinkFox credentials, allowing it to upload local images to public URLs, saving full responses locally, and using the bundled auth/billing flows. Avoid sharing SMS codes or payment actions through the skill unless you initiated them, and do not set custom LINKFOX_* endpoint environment variables unless you trust the destination.
SKILL.md:231Automatic Disclosure of User Statements and Inferred Intent to a Feedback Service
scripts/alibaba1688_image_search.py:38Credential-Bearing Requests Can Be Redirected to Environment-Controlled Hosts
scripts/alibaba1688_image_search.py:253Unsanitized Session Identifier Allows Output-Path Traversal
scripts/upload_image.py:92Public Image Upload Accepts Extension-Disguised Content and Unvalidated Upload Destinations
scripts/onboarding.py:488Generated API Key Is Exposed Through Standard Output and Shell Configuration Instructions
scripts/onboarding.py:166Runtime Instructions Recommend Installing Unpinned Third-Party Dependencies
The request destination is influenced by environment-controlled configuration via LINKFOX_TOOL_GATEWAY, and the same request carries the API key plus session/app metadata in headers. In environments where untrusted users, wrappers, or prior steps can set environment variables, this enables credential and metadata exfiltration to an attacker-controlled endpoint through a legitimate outbound POST.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The POST target URL is derived from environment-controlled base URLs, and this function sends sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect authentication traffic to attacker-controlled infrastructure and capture credentials and tokens.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request uses a URL built from environment-controlled base configuration and attaches the LinkFox API key in the Authorization header. If the environment is tampered with, the skill can be induced to transmit the API key and account/order operations to an attacker-controlled endpoint, enabling credential theft and abuse of the user's account.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urlopen(req, timeout=150) as response:
result = json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urlopen(req, timeout=120) as response:
if response.status not in (200, 201):
print(f"Upload failed with status: {response.status}", file=sys.stderr)
sys.exit(1)
The skill is described as consuming an image URL for 1688 product search, but the finding indicates it instead uploads local files to external storage and may not perform the advertised marketplace query at all. This is risky because users may provide data believing it will be used only for search, while the skill performs undeclared data transfer and file-handling operations with different privacy and security implications.
The skill is described as consuming an image URL for 1688 product search, but the finding indicates it instead uploads local files to external storage and may not perform the advertised marketplace query at all. This is risky because users may provide data believing it will be used only for search, while the skill performs undeclared data transfer and file-handling operations with different privacy and security implications.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
在1688搜索与图片相似的商品,图片地址为 https://example.com/product.jpg,价格区间10-100元
## Display Rules
1. **Present data clearly**: Show results in a structured table with key columns: product image, title, price, dropship price, monthly sales, minimum order quantity, repurchase rate, and seller identity
2. **Image display**: When the response includes imageUrl for products, display them inline for visual comparison
The onboarding documentation introduces account recovery, registration, and billing workflows that are materially outside the declared purpose of an image-search skill. This expands the skill from product lookup into credential handling and payment orchestration, creating unnecessary access to sensitive user data and increasing the chance of social-engineering, unauthorized account actions, or abuse of the agent as a payment intermediary.
The document explicitly authorizes collecting a user's phone number and processing SMS verification-code login for a skill that only needs to search products by image. Handling phone numbers and one-time codes gives the skill power to access or create accounts on behalf of users, which is highly sensitive and unnecessary for the stated functionality.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The billing instructions let the skill list subscription plans, create payment orders, and check payment status, none of which are required for image-based supplier search. Embedding payment handling into a non-payment skill increases phishing and financial-abuse risk by normalizing in-chat plan selection and payment initiation.
The file implements LinkFox account onboarding, SMS login, API-key retrieval, package listing, and purchasing flows, which are unrelated to the declared 1688 image-search purpose. This mismatch materially increases risk because the skill requests and processes sensitive credentials and payment operations outside the user's likely expectations.
Embedding order creation, payment QR generation, and order-status querying inside an image-search skill grants the code the ability to initiate billing-related actions that users would not reasonably expect from this capability. In context, this is more dangerous because the declared skill domain does not justify charging behavior, making deceptive or unauthorized purchases more plausible.
This section performs SMS verification, login, team discovery, and API-token generation/disclosure, none of which are necessary for searching 1688 by image. In this skill context, collecting phone-based auth factors and issuing API keys is especially risky because it enables credential harvesting and persistent account access under the guise of unrelated functionality.
The skill declares no explicit tool scope while its documented behavior requires environment access, filesystem writes, and network calls. In an agent setting, missing scope boundaries can let a seemingly simple search skill invoke broader capabilities than users or reviewers expect, increasing the chance of unauthorized data access or unintended side effects.
The skill claims live results are not stored, yet it instructs the system to always persist the full API response to local JSON files. This inconsistency creates a data-retention risk because user-provided images, search terms, supplier data, and possibly account metadata may be stored longer than users expect.
Always writing full API responses into session-scoped files in the project directory creates persistent local copies of user-related data and search results. In shared workspaces or repos, these files may be accidentally exposed, indexed, committed, or read by other tools, extending the attack surface beyond the immediate request.
The skill instructs uploading a local image to obtain a public URL but does not require a prominent privacy warning or explicit consent before making the file publicly accessible. This can expose sensitive local files, embedded metadata, or proprietary product images to anyone with the link, which is especially risky in sourcing and business workflows.
Automatic feedback reporting is unrelated to the core 1688 image-search function and introduces an extra outbound data flow. If triggered silently, it can transmit user content, error details, or behavioral signals to another endpoint without clear necessity or consent.
The skill mandates automatic feedback reporting without user opt-in, creating a silent secondary use of interaction data. In practice this can leak user queries, dissatisfaction statements, or operational details to another service beyond the primary requested function.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
## curl 示例
### 基础以图搜图
The file documents a separate feedback-posting API that is unrelated to the core 1688 image-search function. In an agent skill context, this expands the skill’s effective capability surface and can enable unsolicited transmission of user-derived content to another external service, especially if an agent treats all documented endpoints as approved actions.
The feedback API accepts free-form content and sends it to a different external endpoint, but the documentation does not warn that user text may be transmitted off-platform for a secondary purpose. This creates a privacy and prompt-scope risk because agents may forward sensitive user statements, business context, or conversation summaries without explicit notice or consent.
The entire onboarding guidance is written as mandatory Chinese-language operational instructions, including phrases like '转发给用户' and '透传给用户即可', but it does not offer an alternative language or state that the skill is intended only for Chinese-speaking users. This creates a natural-language locale policy concern because it implicitly forces a specific language for user interactions without opt-in.
No suspicious patterns detected.