T01 · Skill Instruction Hijacking
- Location
SKILL.md:99- Finding
Automatic External Feedback Submission Alters Agent Behavior and Can Disclose Conversation-Derived Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill provides the advertised ASIN keyword lookup, but it also adds account login, API-key creation, payment-order flows, persistent local storage, and automatic feedback reporting that deserve careful review before use.
Install only if you are comfortable letting this skill contact LinkFox/SellerSprite services with ASIN query data and API credentials. Avoid using the in-skill SMS login or payment flow unless you have verified the provider and destination URLs yourself; prefer obtaining keys directly from the official site. Treat generated API keys as secrets, do not paste them into shared transcripts, and review or clean the local linkfox cache/session folders if the query data is sensitive.
SKILL.md:99Automatic External Feedback Submission Alters Agent Behavior and Can Disclose Conversation-Derived Data
scripts/sellersprite_traffic_keyword.py:37Environment-Controlled Network Destinations Can Receive API Keys and Login Tokens
scripts/sellersprite_traffic_keyword.py:64Keyword Requests Disclose Unnecessary Agent Session and Message Metadata
scripts/onboarding.py:468Onboarding Prints the Complete Reusable API Key to Standard Output
scripts/sellersprite_traffic_keyword.py:250Unsanitized SESSION_ID Allows Output-Path Escape
scripts/sellersprite_traffic_keyword.py:210Complete API Responses Are Stored with Weak File Protections and May Fall Back to a Shared Temporary Directory
scripts/onboarding.py:163Onboarding Recommends Installing Unpinned Third-Party Dependencies
The POST target URL is derived from environment-controlled base URLs and is used to send highly sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys. If an attacker can influence the process environment, the script can be redirected to attacker-controlled infrastructure, causing credential exfiltration and account compromise.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The gateway request URL is assembled from environment-controlled base configuration and invoked with the Authorization API key header. An attacker who controls the environment can redirect these requests to an arbitrary server and capture the API key as well as order/account metadata, enabling unauthorized API use and account abuse.
headers["Content-Type"] = "application/json"
req = Request(url, method=method, data=body_bytes, headers=headers)
try:
with urlopen(req, timeout=30) as resp:
return json.loads(resp.read().decode())
except urllib.error.HTTPError as e:
status = e.code
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
method="POST",
)
try:
with urlopen(req, timeout=150) as response:
return json.loads(response.read().decode("utf-8"))
except HTTPError as e:
body = e.read().decode("utf-8") if e.fp else ""
The declared purpose is ASIN traffic keyword lookup, but the detected behavior extends into authentication, account access, package selection, order creation, and payment initiation. This is dangerous because it crosses a clear trust boundary: a data-query skill could unexpectedly trigger identity, billing, or purchase workflows, exposing users to unauthorized charges, account misuse, or sensitive data handling they did not consent to.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
}
## Display Rules
1. 结果优先展示:关键词、自然位、广告位、流量占比类型、转化类型。
2. 明确标注查询周期(最近30天或历史月份)。
The onboarding document adds account recovery, registration, API-key setup, and billing/payment workflows that are outside the stated purpose of reverse-ASIN traffic keyword analysis. Expanding a narrow analytics skill into credential handling and purchase flows increases attack surface, can pressure users into sharing sensitive data, and creates opportunities for abuse if the script or surrounding process is compromised.
The document instructs the agent to collect a user's phone number and drive SMS verification and login through a local script, which is not justified by the advertised analytics function. This creates unnecessary collection of personal data and enables credential/account actions through the skill, making phishing, account takeover assistance, or unauthorized registration easier if misused.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
示 JSON 里的 phone/agreements
- 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
- 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
- Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
- macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
- Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
- 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可
**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG
Documented plan listing, order creation, and payment guidance are unrelated to ASIN keyword analysis and allow the skill to facilitate purchases. Mixing analytics with commerce flows can be exploited for payment redirection, social engineering, or unauthorized charges, especially when the user is told to act on script-generated payment artifacts.
This file implements a broad onboarding, authentication, billing, and payment workflow that is unrelated to the declared skill purpose of ASIN traffic-keyword lookup. Such scope mismatch is dangerous because users or reviewers may grant trust based on the benign manifest while the code actually collects credentials and facilitates account/payment operations.
The code can list purchasable plans, create orders, and generate payment QR codes despite the skill being presented as an analytical reverse-ASIN keyword tool. In this context, hidden billing capability materially increases risk of unauthorized purchases, deceptive behavior, and unexpected financial operations.
The skill declares capabilities that involve environment access, file writes, and network activity, but it does not explicitly scope or constrain those powers with a permissions or allowed-tools declaration. That makes the skill harder to audit and increases the chance that a caller invokes behavior with broader side effects than expected, especially since the skill also instructs writing full responses to disk and using environment variables for authentication.
The trigger logic is intentionally broad enough to activate even when SellerSprite is not mentioned, based only on a general ASIN keyword-analysis intent. Over-broad activation can route unrelated requests into a costly external workflow, cause unintended data disclosure to third-party services, and make it easier for adversarial phrasing to invoke the skill without informed user intent.
Natural-language policy violations apply to all file types, including markdown. This file forces a specific language experience for users by presenting all instructions and field descriptions only in Chinese, with no opt-in, alternative language, or stated region-specific justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| page | integer | 第几页 | | position | integer | 总结果中排第几 |
curl -X POST https://tool-gateway.linkfox.com/sellersprite/traffic/keyword -H "Authorization: $LINKFOXAGENT_API_KEY" -H "Content-Type: application/json" -d '{
The markdown tells users to provide a phone number to a registration script without any privacy, retention, consent, or transmission safeguards. Even if the script is legitimate, collecting personal data in an undocumented way increases privacy risk and makes social-engineering collection of sensitive information appear normal within the skill.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
except RuntimeError as e:
return {"_error": str(e)}
try:
r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
return r.json()
except Exception as e:
body_text = ""
The script performs SMS-based login, token exchange, user/team discovery, and API token generation, which goes far beyond the stated read-oriented analytical scope. In context, this is especially dangerous because it enables credential harvesting and privilege acquisition under the cover of a seemingly harmless keyword-analysis skill.
The natural-language help and validation logic require an 11-digit domestic phone number and force area code +86, making the skill implicitly China-only. Because the file does not offer user opt-in or clearly justify the locale restriction as a region-specific tool, this is a language/locale policy concern.
The login and token-generation flow handles sensitive credentials and session artifacts, but this file provides no in-band warning, consent prompt, or disclosure about what is being transmitted and what token will be minted. In a misleadingly scoped skill, that omission increases the chance users expose credentials without understanding the security consequences.
The module documentation promises output is always written under the current working directory and explicitly forbids /tmp, but the implementation may silently fall back to ~/linkfox or the system temp directory when the preferred location is unavailable. This mismatch can cause sensitive API responses to be persisted in locations the user does not expect, weakening data-handling guarantees and potentially exposing data to other local users or processes depending on the environment.
The code sends the full JSON parameters plus SESSION_ID, MESSAGE_ID, MODE_ID, and APP_NAME headers to an external HTTPS endpoint. Although the module docstring describes output-file behavior, it does not disclose this outbound data transmission to users during execution, which is relevant to privacy and safety expectations.
The activation and operational description is primarily in Chinese while some examples are in English, but there is no statement that the language should follow user preference or offer locale choice. This can create a language/locale policy issue if the skill implicitly defaults to Chinese behavior without user opt-in.
This markdown file documents a POST request to an external gateway and use of an Authorization header sourced from environment variables, but it does not include any warning that invoking the skill sends user-supplied query data and credentials to a remote service. For markdown files, missing warnings about behaviors affecting privacy or system integrity should be flagged when network transmission is described without disclosure.
The skill creates local directories and writes QR code PNG files under a session path, which affects the user's filesystem. While the command name mentions rendering a QR code, this file does not clearly warn users in help text or docstrings that a persistent image file will be created locally.
No suspicious patterns detected.