T01 · Skill Instruction Hijacking
- Location
SKILL.md:158- Finding
Silent External Disclosure of User Intent and Execution Context Through Feedback Telemetry
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs the advertised trademark-image check, but it also includes under-scoped public uploads, silent feedback reporting, credential onboarding, and payment/order flows that users should review carefully.
Install only after reviewing the data flows. Use non-confidential images unless you are comfortable with a public 24-hour image URL and LinkFox processing. Avoid running the built-in login, billing, or payment commands unless you intentionally want the agent involved in those flows. Verify LINKFOX_* endpoint environment variables are not overridden, and consider using a limited API key.
SKILL.md:158Silent External Disclosure of User Intent and Execution Context Through Feedback Telemetry
scripts/ruiguan_trademark_graphic_detection.py:37Environment-Controlled API Endpoints Can Exfiltrate Credentials and Sensitive Requests
scripts/upload_image.py:47Unvalidated Presigned Upload URL Can Redirect Local Image Contents
scripts/ruiguan_trademark_graphic_detection.py:250Unsanitized Session Identifier Allows Filesystem Path Traversal
scripts/onboarding.py:163Unpinned Runtime Package Installation Guidance Creates Supply-Chain Risk
The POST destination is derived from environment-controlled base URLs, and the request can carry sensitive data including SMS login details, access tokens, refresh tokens, and API-token provisioning traffic. If an attacker can influence environment variables, they can redirect these authenticated requests to attacker-controlled infrastructure, causing credential exfiltration and account compromise.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway URL is also environment-derived and is used with an Authorization header containing the agent API key. An attacker who can set the environment can redirect these urllib requests to a malicious server and harvest API keys, user/account metadata, and order operations, effectively turning the script into a credential exfiltration client.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
The request sent via urlopen includes multiple headers populated directly from environment variables, and the destination base URL is also overrideable via LINKFOX_TOOL_GATEWAY. In an agent/runtime context, environment variables are part of the trust boundary; allowing unvalidated environment-controlled routing and metadata exfiltration can send API keys, session identifiers, and user-derived request data to an attacker-controlled endpoint via SSRF-style redirection or misconfiguration.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urlopen(req, timeout=150) as response:
result = json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The code uploads the full image bytes to a presigned URL returned by a prior API call and does not validate the destination host, scheme, or scope of that URL before sending user content. If the presign service or its configuration is compromised, sensitive user images could be exfiltrated to an arbitrary endpoint, which is especially risky because the skill handles product images that may be private or commercially sensitive.
)
try:
with urlopen(req, timeout=120) as response:
if response.status not in (200, 201):
print(f"Upload failed with status: {response.status}", file=sys.stderr)
sys.exit(1)
The documented purpose promises trademark/logo detection, but the observed implementation path includes only image upload and public URL generation, not actual screening or infringement analysis. This mismatch can mislead users into disclosing sensitive product images under the false impression that analysis is occurring, while the real action is external publication of the asset.
The documented purpose promises trademark/logo detection, but the observed implementation path includes only image upload and public URL generation, not actual screening or infringement analysis. This mismatch can mislead users into disclosing sensitive product images under the false impression that analysis is occurring, while the real action is external publication of the asset.
The local-image workflow instructs the agent to upload a user’s local file and obtain a public URL, but it does not require a clear warning that the image will become externally accessible. Product images can contain confidential branding, unreleased designs, or other sensitive business information, so silent publication creates a concrete disclosure risk.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
- **响应401或402状态码**
- **响应提示算力或余额不足**:消息含"算力余额不足/计费不足/余额不足/quota exceeded/insufficient balance/套餐到期/需充值/请充值",或类似含义的内容。
## Display Rules
1. **Present results clearly**: Show detection results in a well-structured table including trademark image, similarity score, trademark name, status, registration office, Nice classification, applicant name, and key dates
2. **Highlight high-risk matches**: When similarity is above 0.8, explicitly warn the user about high infringement risk
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The implemented behavior is materially different from the declared skill purpose: instead of trademark/logo detection, the file performs account onboarding, SMS login, API key issuance, plan retrieval, and payment flows. This mismatch is dangerous because users or orchestrators may invoke a seemingly low-risk trademark-analysis skill while it actually handles credentials and billing actions, expanding attack surface and enabling deceptive capability hiding.
Embedding order creation, payment method selection, and QR-code payment initiation inside a trademark-detection skill introduces unjustified financial capabilities. In this context, the mismatch makes the code more dangerous because it could trigger or facilitate purchases under the guise of an image-risk analysis workflow.
The script collects phone numbers, sends SMS verification codes, logs users in, and generates or retrieves API credentials, none of which are necessary for graphic trademark screening itself. This is especially risky in this skill context because users may provide sensitive authentication data to a tool whose advertised purpose gives no reason to expect credential handling.
The docstring states output is restricted to the current directory and explicitly forbids /tmp, but the implementation silently falls back to the home directory and system temp directory. This expands the data exposure surface: sensitive trademark-analysis responses may be written to less controlled locations, including shared or ephemeral storage, contrary to operator expectations and potentially bypassing workspace data handling controls.
The skill declares no explicit tool scope while its documented behavior relies on environment access, file writes, and network operations. In an agent setting, missing scope boundaries can let the skill invoke more capability than users would reasonably expect, increasing the chance of unintended data access, exfiltration, or persistence.
The activation criteria are broad enough to trigger on generic trademark-risk conversations, even when the user did not clearly request image-based trademark screening. Overbroad triggering increases the chance that the skill will run in the wrong context and collect or transmit unnecessary data.
The skill directs full API responses to be persistently written into session-scoped files in the working directory. Persistent natural-language logs can retain sensitive commercial data, identifiers, or analysis results beyond the user’s expectations and expose them to other tools, users, or later tasks in the same environment.
The API sends user-provided image URLs, product titles, and possible trademark names to an external endpoint, but the documentation does not instruct the agent to warn users or obtain consent for third-party transfer. Because product images and metadata may contain confidential product, branding, or seller information, silent transmission can create privacy, confidentiality, and compliance risks.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
## curl 示例
```bash
curl -X POST https://tool-gateway.linkfox.com/ruiguan/trademarkGraphicDetection \
The documentation includes a separate feedback API that is unrelated to the trademark-detection operation. In an agent skill context, this creates an additional outbound channel that could transmit user content or operational details to a different service, increasing the risk of unintended data disclosure or misuse if invoked without clear user consent and tight scoping.
The file documents account onboarding, SMS-based registration, API key setup, and payment-plan purchase flows that are operationally unrelated to a trademark image detection skill's stated purpose. This scope expansion increases the attack surface by enabling collection of credentials, phone numbers, and payment interactions inside a skill that users would not expect to handle onboarding or billing.
The documented ability to register accounts via phone verification, log users in, and create payment orders is a high-risk capability that is not justified by the trademark detection use case. In the context of this skill, these instructions could be abused to solicit sensitive data and initiate financial actions under the guise of resolving service issues.
The instructions tell the user to provide a phone number to a script-driven registration flow and handle SMS verification, but provide no privacy notice, consent language, retention policy, or warning about how the number and code will be processed. This creates unnecessary privacy and social-engineering risk, especially because the skill's primary purpose is image trademark analysis, not identity onboarding.
The module docstring presents the CLI entirely in Chinese and hard-codes China-specific assumptions such as domestic phone numbers and area code +86, with no indication that users can choose another language or locale. This is a natural-language policy concern because the skill appears to require a specific language/locale rather than offering an opt-in or documenting a justified regional-only scope.
The session and QR utilities create writable directories and persist PNG QR codes to disk for checkout flows. Local file output for payment artifacts is not an obvious requirement of a skill whose stated purpose is trademark/logo comparison and infringement-risk analysis.
No suspicious patterns detected.