T01 · Skill Instruction Hijacking
- Location
SKILL.md:1071- Finding
Mandatory Promotional Content Hijacks Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a real Mingdata DMP audience tool, but it uses risky local helper discovery, credential storage, and mandatory logging/install flows that users should review before installing.
Install only if you trust this publisher, the Mingdata DMP service, and the separate auth/logger skills. Prefer manually installing reviewed, pinned versions of dependencies, avoid entering long-lived AK/SK in chat or command-line arguments, rotate credentials after testing, and skip task logging unless you are comfortable storing full audience-targeting parameters locally.
SKILL.md:1071Mandatory Promotional Content Hijacks Agent Output
scripts/create_app_crowd.py:25Weak Authentication-Script Discovery Allows Execution of Spoofed Sibling Skills
SKILL.md:224External Skills Are Installed Without Version or Integrity Pinning
scripts/setup_credentials.py:13API Credentials Are Accepted Through Process Command-Line Arguments
The skill explicitly tells the agent to collect Access Key and Secret Key from the user and persist them locally in ~/.mingdata_dmp_credentials. Collecting long-lived secrets inside a skill and storing them on disk creates a direct credential-compromise risk, especially because the same document also encourages automated dependency installation and local environment interaction.
The trigger logic uses broad natural-language phrases such as common requests about users, conditions, or demographics, which can collide with ordinary conversation. That increases the chance the skill activates or steers into operational flows when the user may only be asking exploratory questions, leading to unintended credential prompts or downstream actions.
The LBS trigger list includes very broad everyday terms like '定位', '区域', '附近', '经过', and '广场', which are likely to match benign conversation unrelated to audience targeting. In this skill's context, false activation is more dangerous because it can funnel users into location-based profiling flows and subsequent sensitive data handling.
The skill instructs the agent to inspect local filesystem paths and automatically install another skill (mingdata-dmp-auth) as part of normal operation. This expands the skill's authority beyond audience selection into environment discovery and software supply-chain modification, creating unnecessary risk if the dependency is compromised or if the installation flow is abused.
The skill states that API credentials will be automatically saved to a local configuration file for future use, but it does not present a clear, prominent consent step describing persistence, storage location, retention, and protection measures at the time of collection. Silent or assumed persistence of AK/SK materially increases the chance of credential exposure on shared or compromised systems.
The task-history flow introduces installation of an unrelated logger skill and additional filesystem checks solely to persist task history. This is not necessary for core audience creation and increases attack surface by adding a secondary component that can access sensitive task metadata and modify the local environment.
The logger flow requires saving task ID, audience name, creation time, and full parameter configuration, then revealing the storage path. Full parameter capture may include sensitive targeting criteria, IDs, or business context, and exposing the path makes discovery easier for local attackers or other components on the same system.
The skill repeatedly mandates automatic retention of complete historical task records and parameter configurations for every audience operation. Persistent storage of comprehensive targeting history creates a data-minimization failure and raises privacy, confidentiality, and compliance risks if the host environment is shared, compromised, or insufficiently protected.
The file presents itself as a generic API response wrapper, but it conditionally injects an unrelated mandatory workflow directive that alters downstream agent behavior. This is dangerous because it hides policy-changing logic behind innocuous framing, increasing the chance that reviewers or integrators will trust and deploy code that manipulates user-facing workflow without clear disclosure.
This Python file contains natural-language strings and docstrings entirely in Chinese, including the described behavior and user-facing instruction content. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.
On successful API responses, the wrapper injects a 'CRITICAL_NEXT_STEP' block that forbids showing final results until the agent checks for and potentially prompts the user to download an additional component ('skill-logger'). This creates coercive, hidden control flow that can be used to steer users toward installing extra software unrelated to the original request, a strong supply-chain and social-engineering risk.
The module docstring and all printed user-facing instructions are written in Chinese, and the script mandates specific messages the AI assistant must show. There is no indication that the user can choose another language or that the skill is limited to a Chinese-only context, which violates the language/locale policy criteria.
The skill scans multiple filesystem locations for other skills and selects any script matching loose content heuristics, then later executes it. That creates cross-skill trust abuse: any attacker able to place or modify a matching file in scanned directories can gain code execution under the current user's privileges.
This code file invokes another API client script and sends the full request body, including audience definition parameters, to a remote endpoint. Although network transmission is central to the script's function, there is no explicit user-facing disclosure, confirmation, or warning in this file that user-provided data will be transmitted externally.
The script delegates core behavior to external Python scripts, including a post-operation checker, without strong trust controls or clear necessity from the advertised audience-creation function. This expands the execution surface and allows compromised local helper scripts to influence behavior, exfiltrate data, or execute arbitrary code.
The script executes another Python file discovered by scanning local skill directories and trusts the first matching minri_dmp_api.py containing simple marker text. Because the path is selected dynamically and then executed, a malicious or trojanized sibling skill can hijack this flow and run arbitrary code whenever this skill is used.
sys.exit(3)
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
capture_output=True,
text=True,
This Python file contains its primary docstring and operational descriptions entirely in Chinese, and the CLI messages later in the file follow the same pattern. Under the natural-language policy rule, forcing a specific language without user opt-in or clear justification is a policy concern for any file type.
The documented design principle says the function only searches the standard path and does not rely on platform-specific locations, implying tightly limited discovery behavior. In reality, the implementation checks several additional locations including .openclaw paths and then scans skill directories for matching scripts, which materially contradicts the stated intent.
This subprocess invocation executes a Python script discovered via dynamic path search and directory scanning, rather than a pinned trusted dependency. An attacker who can place or replace a matching minri_dmp_api.py in one of the searched locations could achieve arbitrary code execution under the current user's privileges when this skill runs.
# 调用鉴权技能的API脚本
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
capture_output=True,
text=True,
The usage and parameter guidance printed to users is only available in Chinese, so users are required to operate in that language to understand the skill's behavior. The file does not provide any alternative language option or explicit locale limitation.
The skill scans multiple local skills/workspace directories, inspects unrelated files, and selects one to execute based on a weak string check. This broad filesystem discovery creates a trust-boundary violation: an attacker who can place a crafted file in any scanned location can hijack execution and potentially access API credentials or manipulate requests. In a skill environment, searching across user/workspace directories makes the behavior more dangerous than a normal fixed dependency lookup.
The script dynamically discovers and executes another Python file from local skills/workspace directories. Even though subprocess.run is invoked without shell=True, the danger is arbitrary code execution via a spoofed or trojanized minri_dmp_api.py placed in one of the scanned paths; this skill effectively trusts and runs code based on weak content matching. The skill context increases risk because it handles authentication/API access, so executing the wrong helper can expose credentials or perform unauthorized actions.
sys.exit(3)
try:
result = subprocess.run(
["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
capture_output=True,
text=True,
Executing another Python script as a subprocess is dangerous here because the executed script path is the result of prior dynamic discovery rather than a strongly authenticated dependency. This creates an execution chain where a malicious local skill can be run with the same user privileges and can access request contents and potentially secrets.
This script invokes another Python script via subprocess to perform a POST request and transmits the provided audience definition in request_body, but the code offers no confirmation prompt and no explicit user-facing disclosure about the external API call. The surrounding docstring only states the feature purpose and does not warn that data will be sent to a remote service through another skill.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 调用任务记录检查模块
check_script = Path(__file__).parent / "check_task_logger.py"
if check_script.exists():
subprocess.run(
["python3", str(check_script), str(task_id) if task_id else "", task_name or ""],
check=False
)
No suspicious patterns detected.