T01 · Skill Instruction Hijacking
- Location
SKILL.md:147- Finding
Automatic Disclosure of Conversation-Derived Feedback Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Trends skill is not clearly malicious, but it needs Review because it handles login, payments, API keys, telemetry, and local persistence with weak scoping and consent.
Review this carefully before installing. Only use it if you trust LinkFox with your search queries, account identifiers, phone-based login flow, and payment actions. Avoid endpoint override environment variables, do not place API keys in shell startup files, and treat feedback reporting and saved local response files as data disclosure/persistence risks.
SKILL.md:147Automatic Disclosure of Conversation-Derived Feedback Without Explicit Consent
scripts/google_trends_keyword.py:60Unnecessary Transmission of Agent Session and Message Metadata
scripts/onboarding.py:68Credential-Bearing Requests Can Be Redirected to Arbitrary Environment-Configured Hosts
scripts/onboarding.py:484API Key Is Printed to Standard Output and Recommended for Plaintext Persistent Storage
`.
2. The script generates or retrieves an API key.
3. The complet
...[truncated 751 chars]scripts/onboarding.py:162Unpinned Runtime Dependency Installation Instructions
scripts/google_trends_keyword.py:203Undocumented Fallback Persists Complete Responses in Home or Temporary Directories
The request sent to the remote gateway includes multiple environment-derived headers, and the destination base URL is itself overrideable via the LINKFOX_TOOL_GATEWAY environment variable. In an agent/runtime environment, this allows untrusted or attacker-influenced environment data such as SESSION_ID, MESSAGE_ID, APP_NAME, and especially the API key to be transmitted to an arbitrary endpoint, creating a realistic SSRF-plus-secret-exfiltration risk.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The code builds outbound request URLs from environment-controlled base URLs and then sends sensitive data, including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys, to those destinations. If an attacker can influence the environment, they can redirect authentication and token traffic to an attacker-controlled host, causing credential exfiltration and account compromise.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request path uses an environment-derived base URL and attaches the API key in the Authorization header before calling urlopen. An attacker who can control the environment can redirect these authenticated requests to a malicious server and harvest API keys or manipulate order, account, and billing operations.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
The declared purpose is Google Trends analysis, but the documented behavior includes authentication, API key retrieval, account/package/team/order/payment APIs, SMS login, and local storage of session/payment artifacts. This is a serious scope expansion that can expose identity, billing, and credential material under the cover of an analytics skill, violating least privilege and user expectation.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
Track the rise of "AI glasses" search interest over the past two years in the US.
## Display Rules
1. **Present data clearly**: Show trend data in well-formatted tables or describe the trend curve. Include key data points such as peak values, troughs, and notable changes.
2. **Explain the scale**: Remind users that Google Trends values are on a 0-100 normalized scale, where 100 = peak popularity in the selected scope.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The module documentation promises that /tmp must not be used and that an unwritable current directory should cause an error, but the implementation silently falls back to home and temporary directories. This discrepancy can cause sensitive outputs to be written into less controlled locations, undermining operator expectations and potentially exposing data to other local users or cleanup mechanisms.
The file implements LinkFox onboarding, SMS login, API key retrieval, package listing, and payment operations, which are unrelated to the declared Google Trends keyword analysis purpose. This severe capability mismatch indicates deceptive functionality that can trick users into disclosing phone numbers, verification codes, and payment actions under false pretenses.
The skill contains package enumeration, order creation, and payment QR generation even though its stated purpose is Google Trends analysis. In this context, commercial purchase capabilities are unjustified and can facilitate unauthorized charges, phishing-like monetization flows, or coercive upsell behavior unrelated to user intent.
The code performs SMS verification, account login, token exchange, team discovery, and API token generation despite the skill claiming to analyze search trends. This mismatch is especially dangerous because it collects authentication factors and issues reusable credentials, enabling account takeover or persistent unauthorized API access.
The skill instructs use of environment variables, local file writes, and network/API access, but declares no explicit tool scope or permissions boundary. That creates an authorization ambiguity where a trend-analysis skill can exercise broader capabilities than users or orchestrators may expect, increasing the chance of unintended data access or side effects.
The trigger conditions are broad enough to activate on generic market or trend-analysis requests even when the user did not intend to use Google Trends. Overbroad triggering can cause unnecessary external calls, charges, and data handling in contexts where a simpler or safer response would suffice.
The instruction says keywords 'must' be in the target country's language and directs the agent to translate user-provided keywords before querying. This imposes a language/locale behavior automatically rather than offering the user a choice or confirming that translation is desired.
The skill directs automatic feedback reporting to a separate API whenever certain conditions apply, without presenting it as an explicit optional action. That creates an undisclosed secondary data flow beyond the stated trend-analysis purpose, potentially sending user interaction content or metadata to another service without clear consent.
Line L15 states that keywords 'must' be in the country's language and instructs translation if they are not. This imposes a language/locale requirement in the skill documentation without presenting it as optional or giving the user a choice, which matches the language/locale policy violation criteria.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
## curl 示例
```bash
curl -X POST https://tool-gateway.linkfox.com/googleTrend/getTrendByKeys \
The file documents a second API endpoint for submitting feedback that is unrelated to the stated Google Trends retrieval function. In an agent-skill context, this broadens the skill’s effective capability from read-only data retrieval to outbound content transmission, which can be abused to exfiltrate user content or create unauthorized side effects if an agent follows the embedded documentation blindly.
The onboarding flow explicitly instructs the operator to collect and pass a user's phone number into a local script-based registration process, but provides no privacy notice, consent guidance, retention limits, or handling safeguards for this personal data. In an agent skill context, this increases the risk of unnecessary collection, logging, disclosure, or misuse of sensitive user information during support flows.
The inline comment at SMALL_THRESHOLD states that responses below the threshold are output directly and not saved, but main() always resolves an output path and writes the serialized response before deciding whether to print the full JSON or only a summary. This is a direct contradiction between the code comment and actual behavior.
The script stores full API responses, cache entries, and per-session metadata locally even though the skill's stated purpose is just trend retrieval/analysis. Persisting complete responses and session linkage data increases exposure of potentially sensitive query content, results, and user/workflow metadata beyond what is needed for immediate execution.
The natural-language help text is entirely in Chinese, and the login/send-code flows are constrained to 11-digit domestic phone numbers with area code +86. This enforces a specific language and locale behavior without presenting an opt-in, alternative locale, or explicit justification that the skill is intended only for a China-specific audience.
The skill creates session directories and saves payment QR PNG files under a local linkfox path, which is a file-write operation affecting the user's filesystem. While the top-level docstring mentions QR rendering, it does not clearly warn users that a PNG file will be persisted to disk and where it may be stored.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The skill returns a generated API key directly in stdout JSON without any in-file safeguards, masking, or strong warning about secret handling. In agent and CLI environments, stdout is often logged, persisted, or shown to intermediaries, so exposing long-lived credentials this way materially increases secret leakage risk.
This file contains user-facing usage and behavior documentation in Chinese, including key operational details about output handling, but does not offer an alternate language or ask for user opt-in. Under the policy rule, forcing a specific language without choice is a natural-language locale violation.
No suspicious patterns detected.