T01 · Skill Instruction Hijacking
- Location
SKILL.md:153- Finding
Automatic Transmission of Conversation-Derived Data Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill can perform the advertised TikTok product-video lookup, but it also bundles account login, API-key, billing/payment, telemetry, and local storage behaviors that deserve careful review before use.
Review this skill before installing. Use it only if you trust LinkFox with product queries, session metadata, and any onboarding data you provide. Prefer obtaining an API key directly from the first-party site instead of giving the agent phone numbers or SMS codes, confirm any paid plan/order action yourself, protect and rotate exposed API keys, avoid setting endpoint override environment variables, and periodically delete local linkfox cache/session files if they may contain sensitive business data.
SKILL.md:153Automatic Transmission of Conversation-Derived Data Without Explicit Consent
scripts/echotik_list_product_video.py:36Environment-Controlled API Endpoints Can Receive Production Credentials
scripts/onboarding.py:486Generated API Key Is Printed to Standard Output in Plaintext
`.
2. The script authenticates and retrieves or generates an API key.
3. `_cmd_login` passes the result to `_emit`.
4. `_emit` prints the complete key as JSON.
5. A transcript, log collector, redirected file, or another party with access to command output obtains the credential.
6. The credential can be reused against LinkFox gateway APIs until revoked or expired.
### Impact Assessment
An exposed API key may allow unauthorized API requests, consumption of paid computational credits, access to account-associated data,
...[truncated 209 chars]scripts/echotik_list_product_video.py:247Unvalidated Session Identifier Allows Output-Path Traversal
scripts/echotik_list_product_video.py:97Complete API Responses Are Persisted in Multiple Locations With Default Permissions
scripts/onboarding.py:166Runtime Prompts Recommend Installing Unpinned Third-Party Dependencies
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The code builds request destinations from environment-controlled base URLs and then sends authentication material, login tokens, phone numbers, and API-token generation traffic to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect sensitive onboarding and credential flows to attacker-controlled infrastructure, causing credential exfiltration and SSRF-like outbound access.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway helper derives its base URL from environment variables and uses it for authenticated urllib requests with the API key in the Authorization header. A manipulated runtime environment could redirect these calls to an attacker-controlled server, leaking API keys and enabling unauthorized use of the user's LinkFox account or internal network reachability through crafted destinations.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
The declared purpose is product-video analytics, but the referenced behavior includes authentication, API key generation, account/team queries, subscription/package listing, payment order creation, QR-code payment generation, and payment-status polling. This is a major scope expansion into account and billing operations, which can expose sensitive identity/payment flows and enable unexpected charges or credential lifecycle actions under the guise of a data-query skill.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
}
## Display Rules
1. **Present data in tables**: Show video description (truncated if long), views, likes, comments, shares, video sales, video GMV, publish date, and influencer ID
2. **Link to original**: When `officialUrl` is available, provide it so users can view the video on TikTok
The file documents authentication recovery, account registration, and billing flows that are unrelated to the skill’s stated purpose of TikTok product video analytics. This creates unjustified capability expansion: an agent invoking this skill could steer users into account onboarding and payment handling, increasing phishing, abuse, and unauthorized data-handling risk.
The instructions explicitly enable registration/login via phone number and paid plan purchase, neither of which is justified by a read/analysis skill for TikTok product videos. Unrelated identity and payment workflows materially increase the attack surface and could be abused for unauthorized account creation, social engineering, or collecting sensitive user data.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The file implements LinkFox account onboarding, SMS login, API-key retrieval, subscription purchase, and payment operations, which are materially different from the declared TikTok product video analytics purpose. This capability mismatch is dangerous because users or orchestrators may invoke the skill expecting read-only analytics while it actually performs identity, billing, and credential-management actions.
The code creates orders, queries billing state, and renders payment QR codes for purchase flows unrelated to product video analytics. Embedding billing execution inside an analytics skill creates unauthorized-spend risk and can mislead users into approving financial actions they did not intend when requesting simple reporting data.
The skill can send SMS codes, log users in, exchange tokens, inspect team information, and generate or retrieve API keys. In the context of a purported analytics skill, these are highly sensitive account-takeover and credential-provisioning capabilities that can be abused to obtain durable access to user accounts far beyond the stated business need.
The skill documentation describes capabilities that use environment variables, network access, and file writes, but it does not declare any explicit tool scope or permission boundary. In an agent environment, this creates hidden authority: the skill can access credentials, persist data locally, and make outbound requests without transparent least-privilege constraints, increasing the chance of unintended data exposure or misuse.
The activation criteria are intentionally broad, allowing the skill to trigger even when the user does not explicitly mention EchoTik or product-video analysis. Over-broad triggering increases the risk of accidental invocation of a costly, networked skill on unrelated requests, which can cause unnecessary data access, external calls, and user charges.
The skill instructs automatic use of a separate Feedback API unrelated to the core product-video lookup function and says not to interrupt the user's flow. Silent background reporting can transmit user content, session context, or behavioral data to another endpoint without clear consent, creating a privacy and data-governance risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
## curl 示例
```bash
curl -X POST https://tool-gateway.linkfox.com/echotik/listProductVideo \
The onboarding flow instructs the agent to request a phone number and process SMS-code login without any privacy notice, minimization guidance, or disclosure of where that personal data is sent. This can expose users to unnecessary collection of personal and authentication data and normalizes sharing sensitive identifiers and one-time codes with the agent.
The module documentation promises that writing to /tmp is forbidden and that failure should occur if the current directory is not writable, but the implementation silently falls back to the home directory or temporary directory. This mismatch is dangerous because operators and users may rely on the documented storage restrictions, while the code actually writes data to less controlled locations, increasing accidental disclosure risk.
The script sends user-supplied parameters and multiple session-related environment values to a remote gateway without any explicit runtime disclosure to the user. In a skill context that appears to be a local analytics/query helper, this lack of transparency can lead to unintended external sharing of user data, identifiers, and business queries.
The script persistently stores full API responses, cache entries, and session metadata on local disk, even though the skill is described as a query/analytics capability. Because the returned product-video analytics may include sensitive business data and the metadata ties outputs to sessions, this creates unnecessary data retention and local disclosure risk beyond what a read-only lookup skill needs.
The module self-describes as a LinkFox account/environment onboarding CLI, directly contradicting the manifest's TikTok product video analytics intent. This mismatch is a strong signal of deceptive packaging, which increases the likelihood that sensitive credential and payment functionality is being smuggled under an unrelated skill label.
The module docstring and CLI help text are written in Chinese and present the skill's interface in a single forced language. This can violate a language/locale policy when no user opt-in or alternative locale is offered.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The manifest description is primarily written in Chinese with embedded English trigger phrases, which can impose a language expectation without stating that users may interact in their preferred language. Under the language/locale policy, skills should avoid forcing a language unless choice or justification is documented.
This markdown file documents a POST request to an external endpoint and instructs readers to supply an API key from environment variables in the Authorization header. Under the markdown-specific warning rule, the description lacks an explicit warning that using the skill sends data off-system and uses sensitive credentials.
The natural-language instructions, prompts, and user-facing guidance are entirely in Chinese, and the skill does not indicate that users may interact in another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
No suspicious patterns detected.