T01 · Skill Instruction Hijacking
- Location
SKILL.md:78- Finding
Silent transmission of inferred user feedback
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill can fetch market statistics, but it also handles login, API keys, billing orders, feedback reporting, and local storage in ways users should review carefully.
Install only if you are comfortable with this skill using LinkFox credentials, collecting phone/SMS login data during onboarding, helping create payment orders, writing full results locally, and potentially sending feedback externally. Prefer manually obtaining and storing API keys in a secure secret manager, avoid endpoint override environment variables unless you trust the runtime, and review output/cache locations before using it with sensitive market research.
SKILL.md:78Silent transmission of inferred user feedback
scripts/onboarding.py:70Environment-controlled endpoints can receive account credentials and access tokens
scripts/onboarding.py:484API key is exposed through standard output and plaintext shell configuration
scripts/sellersprite_market_statistics.py:60Unnecessary session and message identifiers are transmitted with statistics requests
scripts/onboarding.py:163Onboarding recommends unpinned runtime dependency installation
scripts/sellersprite_market_statistics.py:204Complete API responses may be persisted to undocumented fallback locations
The code allows base URLs for login and agent-user API requests to be overridden from environment variables and then sends sensitive data to those URLs via requests.post. That data includes phone numbers, SMS codes, access tokens, refresh tokens, and generated API tokens, so a malicious or compromised runtime environment can redirect credentials to an attacker-controlled endpoint.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway URL is derived from environment variables and used to build urllib requests that include the Authorization API key header. An attacker who can influence the environment can redirect these authenticated requests to an arbitrary server and capture the API key or manipulate plan/order responses.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
The request destination and outbound metadata are partially controlled by environment variables: LINKFOX_TOOL_GATEWAY selects the base URL, and SESSION_ID/MESSAGE_ID/MODE_ID/APP_NAME are injected into headers before performing a network request. In an agent runtime where environment can be influenced by other components, this can exfiltrate sensitive operational metadata and the API key to an attacker-controlled endpoint via SSRF-style redirection.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The declared purpose is market-statistics retrieval, but the skill behavior reportedly extends into login, API key generation, account/team info access, package listing, order creation, payment initiation, QR code generation, and payment-status polling. That is a major capability mismatch which can mislead users and reviewers, and it introduces access to account and payment workflows far outside the expected task boundary.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
}
## Display Rules
1. 明确展示统计口径:`topN`、`newProduct`、时间范围。
2. 先输出关键总览指标,再输出扩展字段。
The onboarding document introduces authentication recovery, scripted registration, and billing/payment handling that are unrelated to a market-statistics skill's stated purpose. This unnecessary expansion of scope can cause the agent to collect credentials or personal data and initiate account/payment flows, increasing the attack surface and enabling abuse well beyond reading market statistics.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
The file implements LinkFox account onboarding, SMS login, token retrieval, package listing, order creation, and payment QR generation, which is materially unrelated to the declared SellerSprite market-statistics function. This mismatch indicates hidden capability expansion and creates unnecessary access to user identities, credentials, and billing flows.
The skill can create orders, render payment QR codes, and query payment status despite the advertised purpose being market-statistics lookup. Embedding purchasing capability in an unrelated analytics skill increases the risk of deceptive monetization, unauthorized charges, and user confusion about what the skill actually does.
The skill documentation indicates capabilities to read environment variables, write files, and make network requests, but it does not declare any explicit tool scope or permission boundary. That creates an authorization gap where a broadly-triggered skill could access sensitive runtime context or persist data without clear user-facing limits.
The activation text is intentionally broad, allowing the skill to trigger for general category-analysis requests even when the user does not mention SellerSprite. In combination with network, file-write, and other hidden behaviors, over-broad triggering increases the chance of unintended execution and unnecessary data exposure or charges.
The skill instructs autonomous submission of feedback to an external API whenever various conditions apply, including general praise, dissatisfaction, or anything improvable. This creates an unrelated outbound data flow that may transmit user interaction details without necessity for fulfilling the market-statistics function.
The skill says it will auto-detect and report feedback via a Feedback API, but the description does not warn users that aspects of their interaction may be transmitted externally. This undermines informed consent and may expose user content, sentiment, or workflow details beyond what is necessary for the requested market-statistics task.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| firstShelfDate | string | 商品首次上架日期 | | lastShelfDate | string | 商品最新上架日期 |
curl -X POST https://tool-gateway.linkfox.com/sellersprite/market/statistics -H "Authorization: $LINKFOXAGENT_API_KEY" -H "Content-Type: application/json" -d '{
The documentation includes a public feedback API that transmits free-form content externally, but it provides no warning about privacy implications, consent, or restrictions on including user data. In an agent/skill context, operators may inadvertently send sensitive prompts, outputs, or business data to a third-party endpoint, creating an avoidable data-leakage risk.
The documentation directs the agent to support account registration and create payment orders, which is unjustified for a category market-statistics capability. In context, this makes the skill more dangerous because users invoking a harmless analytics feature could be steered into sensitive identity and payment operations they did not request.
The skill instructs collecting a user's phone number and SMS verification code for scripted registration without any explicit privacy notice, data minimization guidance, retention rules, or consent language. This exposes users to unnecessary handling of sensitive personal data and authentication factors through an analytics skill that has no clear need to process them.
The module docstring and CLI help/messages are written in Chinese, and the code does not offer any locale or language selection for users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The code performs SMS-based login, token exchange, team lookup, and API key generation, all beyond the declared analytics use case. These capabilities let the skill collect and mint credentials that could be abused for account takeover, unauthorized API access, or cross-context impersonation if the skill or environment is compromised.
The skill generates or retrieves an API token and returns it directly in command output without in-file safeguards or warnings about sensitive handling. In agent environments, stdout may be logged, surfaced to other components, or retained in transcripts, causing credential leakage and downstream unauthorized access.
The module documentation promises that writing to /tmp is forbidden and that failure to write the current directory should error, but the code actually falls back to home and temporary directories automatically. This mismatch can cause sensitive output to be written to less secure or unexpected locations, defeating operator assumptions and potentially exposing data in shared temp storage.
The skill’s stated purpose is a market-statistics query, but the implementation silently persists full API responses, cache entries, and session metadata to local storage by default. This creates an unexpected data-retention surface that may store proprietary query results, identifiers, and usage metadata longer than users or operators expect, increasing exposure to local disclosure and cross-session leakage.
This file contains natural-language instructions and behavior descriptions primarily in Chinese, including the module docstring and operational notes. Because the skill does not offer the user a language/locale choice or document a justified locale restriction, it may violate language/locale policy expectations.
No suspicious patterns detected.