T01 · Skill Instruction Hijacking
- Location
SKILL.md:244- Finding
Mandatory Workflow Redirection and Suppression of Task Results
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate DMP audience-sync purpose, but it asks for sensitive API secrets in chat and can execute spoofable local helper code from broad skill directories.
Review carefully before installing. Do not paste AK/SK secrets into chat; use a secure secret manager or a tightly permissioned local credential file instead. Only install the auth and logger dependencies after verifying publisher, version, and integrity, and avoid using this skill in an environment where untrusted skills can exist in searched directories.
SKILL.md:244Mandatory Workflow Redirection and Suppression of Task Results
scripts/create_sync_task.py:34Arbitrary Python Execution Through Spoofable Authentication Skill Discovery
SKILL.md:87Installation of Unpinned Security-Sensitive Third-Party Skills
SKILL.md:139Long-Lived API Credentials Requested Through the Agent Conversation
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill’s stated purpose is audience synchronization, yet it also orchestrates task-logger installation checks and AI-facing control instructions unrelated to the core API operation. That expands behavior into local modification and persistence features that users may not reasonably expect from the description.
The skill’s stated purpose is audience synchronization, yet it also orchestrates task-logger installation checks and AI-facing control instructions unrelated to the core API operation. That expands behavior into local modification and persistence features that users may not reasonably expect from the description.
The skill explicitly instructs users to paste Access Key and Secret Key directly into chat, creating a direct natural-language collection path for highly sensitive credentials. Chat channels are often logged, retained, or visible to intermediaries, so this practice can lead to credential disclosure and downstream API compromise.
The skill describes shell execution and local file/path inspection but does not declare any tool scope or allowed-tools restrictions. That creates an authority gap where an agent may be induced to use filesystem and terminal capabilities without explicit least-privilege boundaries, increasing the chance of unintended local actions.
The skill instructs the agent to install an additional skill via terminal command, effectively granting package-management and environment-modification behavior beyond normal audience synchronization. Installing external components increases supply-chain and local compromise risk, especially if the source or integrity of the installed skill is not strongly verified.
The logging flow similarly instructs installation of a separate task-logging skill, modifying the local environment for a non-core feature. Even if optional, this broadens the attack surface and creates persistence/storage behavior that may surprise users.
The task-logging flow mandates automatic recording of task parameters, which may include sensitive account identifiers, audience metadata, or other user-supplied information. Persisting such data locally without prior granular consent or minimization increases exposure through local file access, retention, and secondary use.
Broad trigger phrases can cause the skill to activate on ordinary conversation, which is risky because this skill can lead to credential handling, local checks, and shell-based installation flows. Overbroad activation increases the chance of unintended execution of sensitive workflows.
The query triggers are underspecified and could match vague user requests without sufficient scope or parameter constraints. In a skill that can inspect local state and process task identifiers, ambiguity raises the risk of accidental data access or unintended workflow entry.
This Python file contains user-facing documentation and printed instructions entirely in Chinese, including required assistant behaviors and user prompts. Because the file does not offer any language/locale opt-in or alternative, it creates a language-policy concern under the rule for forced locale or language.
The module docstring and all user-facing messaging are written only in Chinese, and the instructions presented to the AI assistant are framed as mandatory behavior without any opt-in or language-selection mechanism. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.
The script scans multiple local skill directories, enumerates candidate skills, and opens their files to inspect content in order to discover an auth helper. This exceeds the minimum access needed for audience-sync task creation and creates an unnecessary local-discovery capability that could expose filesystem structure, interact with unintended scripts, or execute a malicious lookalike auth skill if one is planted in a searched location.
This code launches another script via subprocess to perform a POST request, passing advertiser/account identifiers and audience data derived from user input. Although the module docstring states the functional purpose, there is no runtime warning, confirmation prompt, or explicit disclosure near the network operation itself before transmitting potentially sensitive business data.
This code file contains natural-language docstrings and CLI output entirely in Chinese, including the skill description and usage/help text. The policy scope includes all file types, and there is no indication that the language restriction is optional, user-selected, or justified as a region-specific tool.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
sys.exit(3)
try:
result = subprocess.run(
["python3", str(auth_skill_path), method, endpoint, json.dumps(request_body, ensure_ascii=False)],
capture_output=True,
text=True,
The script searches multiple user-writable directories, dynamically enumerates skill folders, and selects any minri_dmp_api.py whose first 500 bytes contain matching strings. This creates a trust-boundary violation: an attacker who can place a crafted script in one of those locations can cause this skill to execute arbitrary code under the user's account when query_sync_task.py runs.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
sys.exit(3)
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body, ensure_ascii=False)],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
sys.exit(3)
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body, ensure_ascii=False)],
capture_output=True,
text=True,
This code invokes another script to perform a POST request and passes user-supplied query parameters in the request body, but there is no confirmation prompt, warning message, or explanatory comment disclosing that data will be sent to an external API. The top-level docstring only says the script queries sync tasks and does not explicitly warn about network transmission.
文档中多处把用户回复和系统提示固定为中文用语,例如 L81 要求回复“是/否”,后续也反复要求回复“确认”“修改”“取消”等中文词汇。这会将交互语言默认锁定为单一语言,但未说明可接受其他语言或允许用户自行选择语言。
The script inspects local filesystem paths to determine whether an unrelated 'skill-logger' component is installed, which exceeds the stated DMP audience synchronization purpose and creates unnecessary environment awareness. While it does not execute the logger or exfiltrate data by itself, this kind of host probing can reveal local setup details and can be used to pressure downstream behavior ('must execute') based on the result.
The file's natural-language descriptions and runtime messages are written entirely in Chinese, and the skill does not offer any language selection or indicate that it is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when users are not given a choice or prior opt-in.
The natural-language descriptions and all user-facing messages are written only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a language/locale policy violation.
No suspicious patterns detected.