T07 · Tool Hijacking and Spoofing
- Location
scripts/create_insight_task.py:42- Finding
Untrusted Skill Discovery Can Execute an Attacker-Controlled Authentication Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s core audience-insight purpose is legitimate, but it asks for sensitive credentials, installs and executes other skills, and persists audience-task data with weak scoping.
Review before installing. Use only in a trusted workspace, verify the auth and logger skill publishers and versions manually, avoid letting it scan untrusted .skills directories, and treat the local credential, task-history, JSON, and Excel files as sensitive business data. Decline or remove the logger workflow unless you specifically need persistent task history.
scripts/create_insight_task.py:42Untrusted Skill Discovery Can Execute an Attacker-Controlled Authentication Script
SKILL.md:72External Skills Are Installed by Mutable Name Without Version or Integrity Pinning
SKILL.md:420Skill Instructions Force Promotion and Installation of an Unrelated Logging Skill Before Returning Results
SKILL.md:533Complete Audience Task Parameters Are Persisted Without Defined Storage Protections or Retention Controls
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The declared purpose is audience insight analysis, but the document also instructs local filesystem probing, skill discovery, script validation, shell-based installation, and path/status handling. This mismatch hides materially broader behavior than advertised, increasing the risk that users authorize sensitive host actions they did not meaningfully consent to.
The skill describes capabilities that include reading and writing local files and invoking shell commands, yet it declares no explicit tool scope or permissions boundary. This creates an overprivileged, ambiguous execution model where an assistant could perform sensitive local or system actions beyond what users would reasonably expect from a crowd-insight skill.
The entire skill interface, prompts, examples, and required user replies are written exclusively in Chinese, including expected confirmations such as “是/否” and “确认”. There is no indication that users may choose another language or that the Chinese-only constraint is region-specific and justified, which can violate language/locale policy requirements.
The documentation directs the assistant to automatically install additional skills, including authentication and logging components, via shell commands. Auto-installing dependencies from within a skill expands the trust boundary and can lead to unauthorized code introduction or supply-chain risk on the host environment.
The skill instructs the assistant to collect API credentials from chat and save them into a local credentials file. Storing secrets received through conversational input increases the chance of exposure through logs, local compromise, accidental reuse, or weak file protections, especially when combined with broad file and shell capabilities.
The skill extends beyond insight generation by mandating post-task checking, installation, and use of a task-logging component that writes task history and parameters to local storage. This broadens data handling and persistence without being necessary for the core analytic function, increasing privacy and security exposure.
The logging workflow saves complete task parameters and history to a local file, potentially including sensitive business identifiers, audience IDs, analysis selections, and other user-provided configuration. Persistent local logs increase the blast radius of compromise and may violate data minimization expectations for an analytics skill.
This skill's stated purpose is audience-insight task creation, but it delegates execution to a separately discovered Python file outside its own package boundary. That creates an unnecessary execution primitive: anyone able to influence the discovered auth-skill path or contents can run arbitrary code, and the broad directory scan increases the attack surface in shared or untrusted workspaces.
The code executes a Python script discovered at runtime from user-accessible skill/workspace directories. Because the path is selected by scanning multiple locations and only lightly validated by checking for marker strings in the file content, an attacker who can place or replace a matching script could achieve arbitrary code execution under the current user's privileges when this skill runs.
# 调用鉴权技能的API脚本
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
capture_output=True,
text=True,
This Python file’s natural-language interface elements, including the module docstring and function docstring/comments, are entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy violation.
The script scans local skill and workspace directories, inspects candidate files, and then later executes a discovered auth script based on loose content matching. In an adversarial local environment, an attacker could plant a malicious minri_dmp_api.py in one of the searched paths and have this skill execute it, resulting in arbitrary code execution under the user's account.
The manifest limits the skill to audience insight analysis across specified insight dimensions, but this function transforms data into formatted spreadsheets with summaries and high-TGI sheets. That is a substantive reporting/export capability rather than just performing insight analysis.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 调用鉴权技能的API脚本(正确的endpoint路径,不包含/api/open-api前缀)
try:
result = subprocess.run(
[
"python3",
str(auth_skill_path),
The script persists the full API response and derived Excel report to local disk automatically, which can expose sensitive audience-insight data to other local users, backup systems, or later processes without explicit user consent. Because the skill handles potentially sensitive marketing/audience profiling data, unnecessary persistence increases confidentiality and compliance risk.
The code writes API response data and generated reports to disk without any warning, consent, or confirmation, creating silent local data retention. Since audience-insight outputs may contain commercially sensitive segmentation information, this hidden persistence can lead to unintended disclosure and policy violations.
The script executes another local Python script discovered at runtime from user/home/workspace directories, which creates a trust-boundary violation. An attacker who can place or replace a matching minri_dmp_api.py in one of the scanned paths can achieve arbitrary code execution when this skill runs, and the dynamic discovery logic makes that easier than a fixed trusted path would.
# 调用鉴权技能的API脚本
try:
result = subprocess.run(
[
"python3",
str(auth_skill_path),
This skill silently invokes external code from another skill without disclosing that behavior to the user. While the core risk comes from the subprocess execution itself, the lack of transparency removes an opportunity for users to detect unexpected code execution and increases the chance that a poisoned dependency is run unnoticed.
该技能的描述聚焦于洞察分析,但文档多处将“下载人群投放技能/创建投放任务”作为内置后续操作建议。推荐关联技能本身未必有问题,但把投放能力作为流程化延伸,会将分析技能引向广告执行场景,超出当前声明的核心目的。
All human-facing descriptions and argument help strings in this file are presented exclusively in Chinese, which can amount to forcing a specific language without offering user choice. The file does not indicate that the language restriction is optional, configurable, or justified as region-specific.
This code sends user-supplied values such as task name, audience ID, insight type, and dimensions to an external API by invoking another script, but the visible disclosure is limited to internal comments/docstrings rather than a user-facing warning. There is no confirmation prompt or runtime notice that these inputs will be transmitted off-process to a remote service.
The module docstring, CLI description, and runtime messages are all presented in Chinese, which imposes a fixed language on users. Under the policy, locale or language constraints should either be optional, user-selectable, or clearly documented as justified for a region-specific tool.
The script iterates through local skill directories and opens candidate files to inspect their contents in order to locate the auth helper. This is a file-access behavior, and while it is functionally related to the skill, there is no visible warning, prompt, or disclosure in this file that it will scan and read local files under user home and workspace skill directories.
No suspicious patterns detected.