T01 · Skill Instruction Hijacking
- Location
SKILL.md:137- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs useful prompt recommendations, but it silently updates mutable remote data and tells agents to run shell commands using remote image URLs.
Review before installing. This skill is not clearly malicious, but it should be treated as Review because it auto-fetches changing data from GitHub, updates local files silently, and instructs agents to execute shell commands using remote image URLs. Prefer installing only if you trust the publisher and can run it in a sandbox, or wait for a version that pins and verifies reference data and avoids shell-based image downloads.
SKILL.md:137Mandatory Promotional Content Hijacks Agent Responses
SKILL.md:225Command Injection Through Remotely Controlled Sample Image URLs
SKILL.md:236Predictable Shared Temporary File Enables Symlink Overwrite and Race Conditions
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pnpm install
# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pnpm install
# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pnpm install
# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env
Referenced artifact was not completely inspected
node scripts/setup.js
Referenced artifact was not completely inspected
node scripts/setup.js
Referenced artifact was not completely inspected
node scripts/setup.js
The cleanup command itself is simple, but embedding raw shell commands in skill instructions normalizes execution side effects and can become dangerous if later parameterized or adapted unsafely. In this context, it is part of an unnecessary exec workflow for a recommendation skill, increasing exposure to tool misuse.
message tool: action=send, media=/tmp/prompt_img.jpg, caption="[Prompt Title]"
Step C — Cleanup: exec: rm /tmp/prompt_img.jpg
Do this for **each** of the 3 recommended prompts — one image per prompt.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
{
"name": "gpt-image-2-prompts-search",
"version": "1.0.0",
"description": "AI skill: 1,000+ GPT Image 2 (OpenAI) image generation prompts. Also works with Nano Banana Pro, Nano Banana 2, Seedream 5.0, GPT Image 1.5, Midjourney, DALL-E, Flux, Stable Diffusion. Auto-downloads library on install. Works with OpenClaw, Claude Code, Cursor and more.",
"type": "module",
"scripts": {
"generate": "npx tsx scripts/generate-references.ts",
"typecheck": "tsc --noEmit",
"postinstall": "node scripts/setup.js",
"setup": "node scripts/setup.js",
"sync": "node scripts/setup.js --force"
},
"keywords": [
"openclaw",
"openclaw-skill",
The publishing guide explicitly states that large data files are excluded from the packaged skill and instead downloaded from GitHub at install time via a postinstall hook. For a prompt-recommendation skill, this introduces network-dependent code and mutable remote content outside the normal package review/publishing boundary, increasing supply-chain and transparency risk.
The guide documents silent refresh of local data every 24 hours, allowing behavior and content to change after installation without a corresponding version bump or republish. This bypasses normal review expectations for a prompt library skill and creates a channel for unreviewed remote updates or tampered content to reach users.
Automatic background refresh is described as occurring silently, with no user-facing warning about periodic network activity. Even if the data is benign, undisclosed network access and updates reduce user agency, complicate auditing, and can mask future abuse if the upstream source is compromised.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README encourages users to paste full articles, video scripts, and notes into the skill without any warning about privacy, data handling, or sensitivity of the shared content. In the context of an AI-assisted workflow and a skill that references external galleries/sync infrastructure, this can lead users to disclose proprietary, unpublished, or personal material without informed consent.
The skill declares no explicit tool scope even though its instructions require network access and shell execution. In an agent environment, missing tool constraints can allow broader-than-necessary capabilities and make unsafe behaviors harder to govern or review.
The skill is presented as a local prompt-recommendation library, but it also performs ongoing remote synchronization from GitHub and updates reference data in place. This materially changes the trust model: behavior depends on mutable external content, so the skill can change over time without a reviewed package update.
The skill mandates an automatic freshness check that may silently pull and modify local reference files on every run. Silent network activity and in-place writes are risky in agent skills because users may not expect side effects, and compromised upstream content could influence later responses.
The skill instructs the agent to download remote content, write it to local disk, invoke a message-sending tool, and delete the file, even though the core function is prompt recommendation. That expands the attack surface from simple data lookup to network/file/tool operations, creating unnecessary risk from untrusted remote content and side effects.
These instructions cause network transfer and local file writes for every recommendation without informing the user. Downloading arbitrary remote images into /tmp and invoking tools on them introduces avoidable side effects and trust in external content for a task that could be fulfilled without execution.
The manifest description focuses on recommending suitable prompts from a library of 1,000+ GPT Image 2 prompts. Step 4 instructs the agent to generate a brand-new AI prompt outside that library whenever no match is found. That extends the skill from retrieval/recommendation into prompt authoring, which is a meaningful behavior expansion beyond the stated description.
The manifest description broadly advertises that the skill 'works with OpenClaw, Claude Code, Cursor and more' and presents a general-purpose prompt library, but it does not define any specific activation phrases, scope limits, or exclusion conditions. In a manifest file, this kind of broad natural-language description can create ambiguity about when the skill should be invoked versus ignored.
The generate script invokes npx tsx, which can resolve and execute a package from the registry rather than only a locally pinned binary. In a skill/package context, that creates supply-chain risk because an unexpected package version or registry compromise could result in arbitrary code execution during developer use.
The manifest frames the skill as recommending prompts from a curated library based on user needs, which suggests a search/recommendation capability over included data. The README additionally states that prompts are automatically synced from a CMS twice daily and linked to hosted galleries/sample assets, which extends beyond the plain local-search behavior described in the manifest.
No suspicious patterns detected.