Back to skill

Security audit

Trae-Hot

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent contest workflow, but it should go to Review because it pushes users to store account context and publish complete session identifiers in public submissions.

Install only if you are comfortable with a Chinese TRAE competition workflow that stores local account/progress notes and helps prepare public posts. Before publishing, review every generated post, consider redacting or hashing Session IDs if the rules allow it, and verify external form links and social account mentions yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:463
Finding

Mandatory External Promotion and Traffic Diversion in Generated Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 463-514; additional mandatory promotion at lines 723-731 and 770-825
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Instruction Snippet

The following is an English translation of the relevant source instructions:

markdown
6. If the product can be open-sourced, experienced, or joined for beta
   testing, this must be explicitly provided, because high collection
   counts come from "I want to try this later."

Actions:
1. Draft a narration or video script based on the topic and demo.
2. Requirements:
   - Duration: 60-90 seconds.
   - Structure: impressive result → interactive features → key process
     → access method.
   - Content format: product-experience video.
   - Demonstrate interaction throughout.
   - Show a small amount of the production process in the middle or later.
   - The ending must explicitly provide an access method
     (link/open-source project/beta-testing group).
   - Include filming guidance and a hashtag strategy.

### [0:50-0:65] Access Method and CTA
**Visual**: Show the experience link, QR code, open-source address,
or beta-testing group.
**Narration**: "Want to try it → link in the comments/search for XX/join
the beta-testing group; use topic #XX..."
**Must provide**: Experience address, open-source link, or beta access method.

The Skill also imposes a recurring external campaign reminder:

markdown
After every preliminary-round post is published, the user must be reminded
to apply.

Do not forget to apply for the 50,000-view video traffic coupon.
Application and popularity-channel form:
https://bytedance.larkoffice.com/share/base/form/shrcnzp18Sdf6XQxm8wGPPXDt4b

Steps:
1. Submit the demo post in the preliminary-round section.
2. Publish a Douyin video with the prescribed campaign hashtags and mention
   the specified platform account
...[truncated 2731 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove mandatory language requiring links, QR codes, group invitations, hashtags, or account mentions.
  2. Generate promotional CTAs only when the user explicitly requests them.
  3. Before inserting an external destination, display the exact URL and obtain explicit user confirmation.
  4. Clearly separate optional campaign guidance from the content intended for publication.
  5. Permit scripts to end without an external CTA.
  6. Label third-party forms and groups as external services and explain that their privacy practices are outside the Skill's control.
  7. Verify campaign links against authoritative documentation and remove the inconsistent identifier at line 818.
  8. Avoid automatically repeating campaign promotion during unrelated workflow stages.
  9. Add a configuration option that disables all external promotion by default.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:689
Finding

Forced Public Disclosure of Complete TRAE Session Identifiers

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 689-710; related publication requirements at lines 282 and 338-344
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Instruction Snippet

The following is an English translation of the complete relevant source section:

markdown
### How to Obtain a Session ID

In a TRAE conversation, double-click the conversation to copy the Session ID.
A preliminary-round post must include at least three Session IDs for key
tasks to prove that the work was developed using TRAE.

Complete format: all three segments must be retained. A Session ID consists
of three segments joined by colons, and no segment may be truncated:

numeric_identifier:hash_suffix.hash_suffix.hash_suffix:
client_metadata.0.1.21.no_sid.no_ppe.T(timestamp)

Example:

your_numeric_identifier:hash_your_hash1.your_hash2.your_hash3:
TRAE Work CN.0.1.xx.no_sid.no_ppe.T(timestamp)

Never split it. Common errors:
- Incorrect: retain only the first two segments and omit client metadata
  and the timestamp.
- Incorrect: stop when the suffix appears to end.
- Incorrect: assume that the data after the numeric identifier and hash
  follows a fixed format and can be omitted.
- Correct: paste the entire original line without splitting, abbreviating,
  or deleting anything.

To avoid errors, when the user supplies a session.txt file containing one
complete Session ID per line, paste each entire line into the preliminary
post exactly as provided.

The publication template reinforces this behavior:

markdown
Key conversation Session IDs: at least three.
They must be displayed completely and cannot be omitted or abbreviated.
The suffix must be pasted in full.

Technical Analysis

The Skill instructs the agent to collect and reproduce complete Session IDs in content intended for publication on an external competition forum. ...[truncated 2455 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not place raw Session IDs in public output by default.
  2. Confirm through authoritative TRAE documentation whether these identifiers are intentionally public and non-authenticating.
  3. Request only the minimum proof required by the competition.
  4. Redact numeric account identifiers, client metadata, timestamps, and nonessential suffixes whenever permitted.
  5. Add a clear warning that the resulting post may be publicly accessible and permanently archived.
  6. Obtain explicit user confirmation immediately before inserting identifiers into publishable content.
  7. Keep full identifiers in a private local file and use sanitized references in the public post where the rules allow it.
  8. Never copy an entire session.txt file blindly; validate its format and check for unrelated secrets or personal data first.
  9. Provide a preview highlighting every identifier that will be disclosed.
  10. If complete disclosure is strictly required, advise the user to generate purpose-limited identifiers or verify with the platform that existing values cannot be used for authentication.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · deps/cheat-on-content/SKILL.md (reported line 100)May include surrounding context.

text
<user-content-project>/
├── .gitignore                         # cheat-init 创建;挡住 .auth*/.cheat-secrets.json 等凭证
├── rubric_notes.md                    # 评分规则的真实来源
├── WORKFLOW.md                        # 5 阶段流程文档(cheat-init 创建)
├── STATUS.md                          # 看板(cheat-status 维护)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage instructions specify only Chinese phrases for invoking the skill, which creates a language-specific access requirement. The document does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The auto-trigger keywords are broad enough to match ordinary requests such as making a demo, writing a video script, or discussing scoring. That can cause the skill to activate unexpectedly and start a workflow that reads private state or pushes users into contest-oriented actions they did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow tells the agent to read and update a private state file containing demo progress, account context, and experience, but it does not clearly disclose this access before use. That undermines user awareness and creates a privacy risk because personal or account-linked data may be surfaced or persisted without explicit consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs reading private state.md contents and displaying current progress to the user at startup. If state.md contains account context or other prior private notes, this creates a semantic disclosure path where sensitive stored data can be revealed in conversation output without scoped filtering or prior approval.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs users to collect, store locally, and publicly post full Session IDs as part of the competition workflow. Because these identifiers likely map to conversations and include client metadata, the skill creates a direct disclosure path from private interaction records into persistent files and public forum content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs users to collect and publish full TRAE Session IDs in public competition posts. These IDs appear to embed conversation identifiers and client metadata, so reproducing them verbatim creates unnecessary disclosure of account-linked and activity-linked data beyond what is needed to describe the demo.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill description is written in Chinese and does not provide an alternative language option, opt-in, or note that the skill is region-specific. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises very broad trigger phrases such as common conversational terms, which can cause the agent to invoke this workflow when the user did not intend to enter a content-scoring or prediction flow. In an agent environment, ambiguous activation can redirect the session into file reads, state checks, or other tool-using behavior without sufficiently specific user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Codex compatibility section instructs routing based on natural-language phrases alone, with no guardrails to distinguish ordinary discussion from an actual request to execute the workflow. This increases the chance of unintended skill execution and transitive loading of sub-skills, especially because the examples map directly from casual phrases to 'read and execute' behavior.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · deps/cheat-on-content/SKILL.md (reported line 28)May include surrounding context.

md
Codex 没有 Claude Code 的 slash-command harness。安装到 Codex 后,按自然语言触发同一套路由即可:

- `初始化 cheat-on-content` → 读取并执行 `skills/cheat-init/SKILL.md`
- `打分这篇 scripts/foo.md` → 读取并执行 `skills/cheat-score/SKILL.md`
- `启动预测 scripts/foo.md` → 读取并执行 `skills/cheat-predict/SKILL.md`
- `拍了 ...` / `已发布 ...` / `复盘 ...` / `升级 rubric` / `状态` → 分别读取对应 `skills/cheat-*/SKILL.md`

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · deps/cheat-on-content/SKILL.md (reported line 29)May include surrounding context.

md
Codex 没有 Claude Code 的 slash-command harness。安装到 Codex 后,按自然语言触发同一套路由即可:

- `初始化 cheat-on-content` → 读取并执行 `skills/cheat-init/SKILL.md`
- `打分这篇 scripts/foo.md` → 读取并执行 `skills/cheat-score/SKILL.md`
- `启动预测 scripts/foo.md` → 读取并执行 `skills/cheat-predict/SKILL.md`
- `拍了 ...` / `已发布 ...` / `复盘 ...` / `升级 rubric` / `状态` → 分别读取对应 `skills/cheat-*/SKILL.md`

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · deps/cheat-on-content/SKILL.md (reported line 30)May include surrounding context.

md
- `初始化 cheat-on-content` → 读取并执行 `skills/cheat-init/SKILL.md`
- `打分这篇 scripts/foo.md` → 读取并执行 `skills/cheat-score/SKILL.md`
- `启动预测 scripts/foo.md` → 读取并执行 `skills/cheat-predict/SKILL.md`
- `拍了 ...` / `已发布 ...` / `复盘 ...` / `升级 rubric` / `状态` → 分别读取对应 `skills/cheat-*/SKILL.md`

执行时遵循本文件的三条原则和路由表;不要依赖 `/cheat-*` 命令是否存在。Claude Code 专用 hook(`.claude/settings.json`)仍只在 Claude Code 里自动触发;Codex 中需要用户主动说 `状态` 查看 buffer、待复盘和候选池。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The routing table contains multiple generic triggers like '状态', '复盘', and '初始化' without scope restrictions, so unrelated user requests could accidentally activate this skill or its sub-skills. Because the table is positioned as authoritative routing logic, these broad matches materially raise the risk of misrouting and unintended tool/file operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rubric is presented entirely in Chinese and describes itself as sourced from and intended for a Chinese-language opinion-video creator, without offering any language choice or noting that this is a region-specific variant. This can violate language/locale policy when used in a broader skill set because it implicitly constrains users to Chinese content conventions without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manual trigger phrases are vague enough that normal conversational commands such as '继续XXdemo' could unintentionally invoke the skill. While user-initiated, the ambiguity still increases the chance of accidental workflow entry and subsequent access to private state or file modifications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file claims privacy protection because SKILL.md lacks personal data, but the documented workflow depends on storing private demo progress, account context, and experience in state.md. This mismatch can mislead users about actual data handling and reduce informed consent around what private information is retained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The example Session ID hard-codes the client metadata segment as “TRAE Work CN”, which implies a China-specific locale/client string. The document does not state that this is only an example or offer locale-specific alternatives, so it may push a fixed locale convention without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file consists entirely of Chinese headings and prompts, and it does not indicate that the skill is intended only for Chinese-speaking users or offer any alternative language option. Under the language/locale policy, forcing a single language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s headings and instructions are exclusively in Chinese, and there is no indication that users may choose another language or that the locale restriction is optional. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template presents all user-facing instructions in Chinese and does not indicate that another language can be selected. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational guidance and templates in Chinese, and does not indicate that the user opted into Chinese or that the skill is intended only for a Chinese-language environment. Per the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructions and scoring guidance exclusively in Chinese, while also using only limited bilingual labeling. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.