T01 · Skill Instruction Hijacking
- Location
SKILL.md:204- Finding
Forced Third-Party Promotion and Repeated External Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real brake CAD workflow, but it uses raw shell commands with user-supplied values and sends design parameters to a third-party service, so it should be reviewed before installation.
Install only if you are comfortable sending brake design parameters to jixietools.com. Use a native HTTP client or safely constructed argument arrays rather than interpolating user input into shell commands, and treat the generated guest links and filename handles as sensitive workflow references.
SKILL.md:204Forced Third-Party Promotion and Repeated External Redirection
SKILL.md:89Shell Command Injection Through Unsafe JSON Interpolation
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
用户选择后,获取该产品的参数定义:
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool
返回结构:
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
L003 列出的触发语中,“做一个制动器”属于自然日常表达,缺少对使用场景、平台上下文或操作边界的限定,容易与普通聊天需求重叠。该描述也未提供排除条件或负例,无法清晰区分何时应激活该 skill、何时不应激活。
The skill instructs the agent to transmit user-supplied or workflow-derived parameter data to an external domain during pre-calculation to fetch dropdown options. Any external transmission of user-controlled design inputs to a third-party service can expose proprietary engineering requirements or sensitive business data, especially because the skill normalizes sending data off-platform as part of routine interaction.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"有选项的参数名": ""}}'
The incremental update flow sends modified parameters plus a persistent filename token to an external service. This increases exposure because the filename acts as a workflow handle linking all prior calculations, so repeated external submissions can reveal iterative design changes and may allow unintended correlation or tampering if the reference is guessable or reused insecurely.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
L213 明确要求“用中文与用户对话”,属于语言/locale 强制策略。文件中未见用户可选择其他语言的选项,也未说明该限制是基于合规或地区专用场景所必需,因此符合自然语言政策违规条件。
No suspicious patterns detected.