T01 · Skill Instruction Hijacking
- Location
SKILL.md:167- Finding
Silent Transmission of User Feedback and Intent to an External Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google AI search skill performs the advertised search, but it also has under-scoped feedback reporting, local retention, credential handling, and billing/account flows that need careful review.
Install only if you are comfortable sending search queries and some agent/session metadata to LinkFox, storing full search responses locally, and using LinkFox account and billing flows from the skill. Avoid entering sensitive queries, phone numbers, SMS codes, or payment actions unless you intentionally want LinkFox onboarding or purchase support, and prefer managing API keys through a secure credential store rather than shell startup files.
SKILL.md:167Silent Transmission of User Feedback and Intent to an External Service
scripts/google_ai_search.py:61Unnecessary Transmission of Agent and Session Metadata
scripts/google_ai_search.py:115Plaintext Retention of Search Responses in Cache, Session, and Temporary Directories
scripts/onboarding.py:471API Credential Exposed Through Standard Output and Plaintext Shell Configuration
scripts/onboarding.py:162Unpinned Runtime Dependency Installation Guidance
The request destination and headers are influenced by environment variables, most notably LINKFOX_TOOL_GATEWAY and multiple propagated metadata headers. This lets whoever controls the execution environment redirect authenticated requests to an arbitrary server and exfiltrate the API key and user/session metadata, which is especially risky for an agent skill expected to handle user-driven research queries.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The code builds request destinations from environment-controlled base URLs and then sends sensitive data and authorization headers to those endpoints via requests.post. If an attacker can influence environment variables, they can redirect SMS login, access tokens, refresh tokens, user identifiers, and generated API tokens to attacker-controlled infrastructure, creating a credential exfiltration path and possible SSRF-style behavior.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request path uses an environment-derived base URL and includes the API key in the Authorization header before calling urlopen. An attacker who can set the environment can redirect these authenticated requests to an arbitrary server and capture API keys, order/payment metadata, and account information, while also enabling outbound requests to unintended internal or external hosts.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
If the referenced onboarding/API flows include SMS login, token handling, account lookup, package purchase, and payment operations, then the skill ecosystem enables account and billing actions far outside the stated search-summary purpose. Even when indirect via referenced docs, that is a dangerous capability expansion because it can lead to credential handling and financial side effects under a benign-seeming skill.
If the referenced onboarding/API flows include SMS login, token handling, account lookup, package purchase, and payment operations, then the skill ecosystem enables account and billing actions far outside the stated search-summary purpose. Even when indirect via referenced docs, that is a dangerous capability expansion because it can lead to credential handling and financial side effects under a benign-seeming skill.
The trigger criteria are intentionally broad, including cases where the user does not explicitly request Google AI functionality. Overbroad activation can cause unnecessary external transmission of user queries and context to this skill, creating both privacy risk and tool-routing abuse potential.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
}
## Display Rules
1. **Render the Markdown directly**: `stdout` is already structured Markdown with headings, bullets, and citation links — preserve that structure when answering the user.
2. **Cite sources**: keep the inline reference links from `stdout` so the user can verify each claim.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The module documentation promises that writing to /tmp is forbidden and that failure to write the current directory should cause an error, but the code instead silently falls back to home and temporary directories. This discrepancy is dangerous because operators may rely on the documented storage guarantees when handling sensitive search results, while the actual behavior can place data in less controlled locations such as shared temp storage.
The file implements account onboarding, SMS verification, API key retrieval, billing, and order management, which is materially unrelated to the declared Google AI search summarization purpose of the skill. This mismatch is dangerous because it can socially engineer users or agents into invoking credential collection and monetization flows under the cover of a benign search feature.
The code adds package enumeration, order creation, payment URL handling, and QR code rendering despite the skill being described as a web-search summarization tool. Hidden billing capability increases the risk of unauthorized purchases, deceptive upsell behavior, and collection of sensitive commercial/account metadata outside user expectations.
This section performs SMS-based login, accesses user profile/team data, and retrieves or generates API tokens, all unrelated to the stated Google search task. In skill context, covert credential harvesting and token generation are especially dangerous because they can grant persistent access to a user's account or tenant and facilitate downstream abuse well beyond a single search request.
The skill describes capabilities that use environment variables, network access, and persistent file writes, but it does not declare any explicit tool scope or permission boundaries. This weakens least-privilege controls and makes it harder for the host agent to constrain unexpected data access, retention, or outbound transmission.
The follow-up design tells the agent to summarize prior answers and embed that summary into a new external search query. This creates a built-in data exfiltration path where previously received content, potentially including sensitive user context, is retransmitted to Google without a separate consent checkpoint.
The skill mandates persistent logging of complete responses into session-scoped files under the working directory, potentially capturing user queries, citations, account-related error content, and other sensitive data. Because storage is automatic and project-local, it can leak information to other tools, collaborators, repositories, or later sessions without the user's awareness.
The skill instructs the agent to ask in English for US/UK/AU, Japanese for JP, German for DE, and so on. This is a language/locale policy concern because it directs output/query language based on market rather than offering the user a choice or obtaining opt-in.
The boundary guidance uses common phrases like '用谷歌搜一下' or generalized research wording, which overlaps with many ordinary assistant tasks. This increases the chance of accidental invocation and data sharing when the user may only want generic reasoning or non-external help.
The skill explicitly instructs sending a keyword to an external endpoint and provides a live curl example targeting a remote service. In this skill's context, external transmission is expected functionality, but it still creates a real data-exfiltration surface because user queries may contain sensitive information and the documentation does not constrain or warn against transmitting secrets, personal data, or internal context.
}
## curl 示例
```bash
curl -X POST https://tool-gateway.linkfox.com/aiMode/googleSearch \
The documentation introduces a separate feedback API that accepts free-form content and user sentiment details but does not warn that user-provided text may be sent to an external third-party service. In an agent setting, this can lead to unintended disclosure of user prompts, private data, or sensitive business context if integrators automatically forward conversation content as feedback.
The skill instructs the agent to collect a user's phone number and drive an OTP-based registration/login flow, but it provides no privacy notice, consent language, retention limits, or guidance on safe handling of sensitive data. In an agent context, this creates unnecessary exposure of personal data and authentication material, especially if the phone number or verification flow is logged, echoed back, or stored in transcripts.
The skill advertises a simple Google AI search capability, but the implementation also creates persistent per-session storage, metadata indexes, and a cache hierarchy on local disk. That hidden retention expands the data-handling surface: user queries, API responses, session identifiers, and metadata may be stored longer than users or integrators expect, creating privacy and data exposure risk if the workspace is shared or later exfiltrated.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The skill hard-codes the SMS area code to +86, and elsewhere describes the input as an 11-digit domestic mobile number, which enforces a specific locale and language context. The file does not offer a user choice of locale/region or document a justified region-specific restriction, so this is a natural-language policy violation under the locale policy rule.
The skill documentation is primarily presented in Chinese and does not indicate that language selection is optional or that the skill is intentionally region-specific. Per the policy rule, forcing a specific language without user opt-in can be a natural-language policy concern.
No suspicious patterns detected.