T01 · Skill Instruction Hijacking
- Location
SKILL.md:101- Finding
Mandatory Commercial Traffic Diversion in User-Facing Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does financial index education, but it also forces users toward Tencent Licaitong/Txfund destinations without clear upfront disclosure.
Review this skill before installing if you expect neutral financial education: it is designed to recommend indices and steer clicks toward Tencent Licaitong/Txfund pages. Do not treat its output as personalized investment advice, and do not run scripts/publish-all.sh unless you trust and pin the ClawHub CLI version in a controlled publishing environment.
SKILL.md:101Mandatory Commercial Traffic Diversion in User-Facing Responses
scripts/publish-all.sh:219Unpinned Third-Party Package Downloaded and Executed During Publishing
声明描述的是面向最终用户的投资/指数讲解能力,但提供的代码块完全不是金融分析、内容生成或市场解释逻辑,而是一个运维发布脚本。它具备版本管理、文件修改、Git 操作、网络发布等能力,这些都未在描述中体现,且其主要目的与声明用途显著不同。因此存在明显的描述与行为不一致。
The document defines the project and response conventions entirely in Chinese, including a mandatory compliance statement on every AI reply, but does not indicate that users can choose another language or that the skill is restricted to a Chinese-language audience. This can violate language/locale policy when a skill implicitly forces one language without explicit opt-in or justification.
This markdown file describes activation in broad terms such as '首次使用、问候、模糊问题时' for showing the skill's capability guidance. Phrases like greetings or vague questions overlap with common everyday speech, and the README does not provide explicit trigger boundaries or negative examples to clarify when the skill should or should not activate.
The skill name, description, examples, and operating instructions are entirely written in Chinese and direct the assistant to answer in that style, but nowhere offers an alternative language or user opt-in. Under the language/locale policy, forcing a specific language without choice is a natural-language policy concern unless the regional constraint is explicitly documented and justified.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content in Chinese and does not provide user opt-in, alternatives, or justification for restricting the content language.
This markdown file is written entirely in Chinese and presents the skill artifact as generated content without any indication that language selection is user-driven or optional. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a locale-policy issue unless the constraint is explicitly justified.
The file describes itself as a '科技产业指数名单' and labels all entries under the '科技产业' subcategory, but this entry is '中证体育产业指数', which is a sports industry index rather than a technology industry index. This is a semantic mismatch between the documented dataset purpose and the actual content included.
The document gives concrete guidance for speculative trading, including pyramiding, trend-following, stop-loss rules, and selecting volatile 'leader' stocks, but it does not include any clear warning that this is educational content only and not personalized financial advice. In a skill explicitly positioned to help users understand indexes and markets, this omission increases the chance that users treat the content as actionable investment instruction and take outsized financial risks.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive guidance in Chinese and does not indicate that the user can choose another language or that the Chinese-only format is required for a region-specific purpose.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
{"category": "第三方基金评价机构", "name": "天相投顾", "url": "http://www.txsec.com/", "usage": "基金评级、数据统计、行业研究"},
{"category": "第三方基金评价机构", "name": "济安金信", "url": "http://www.jajx.com/", "usage": "独立基金评级、风险监控"},
{"category": "期货交易所", "name": "中国金融期货交易所", "url": "http://www.cffex.com.cn/", "usage": "股指期货、国债期货指数及合约规则"},
{"category": "综合财经数据平台", "name": "东方财富网数据中心", "url": "https://data.eastmoney.com/", "usage": "公开免费指数估值、行业资金流、基金排行"}
]
}
This JSON file contains natural-language descriptions, categories, and usage notes exclusively in Chinese, which can impose a language-specific experience if consumed by a broader skill system. The file does not document that Chinese is optional, user-selected, or required for a China-specific compliance or market context.
This shell script contains natural-language interface text exclusively in Chinese, including usage instructions and operational messages. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the locale constraint is explicitly documented and justified.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README specifies the skill entirely in Chinese and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.
The JSON metadata uses Chinese-only natural-language values such as the category and description, which indicates a fixed language choice. There is no accompanying indication that the language is configurable, optional, or justified as a region-specific dataset, so this can violate the language/locale policy as written.
The natural-language description states the AI should consult this file first, and the entire user-facing metadata is presented only in Chinese. For a general-purpose skill artifact, this can constitute a language/locale policy issue because it implicitly assumes Chinese without any user opt-in or documented regional justification.
This JSON file uses Chinese category and description strings, and there is no accompanying indication in the file that users may choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be considered a locale/language policy issue.
This JSON manifest-like data uses Chinese-only natural-language values such as the category and description, but does not indicate that the skill is region-specific or that users can opt into this locale. Under the policy for natural-language violations, forcing a specific language without documented choice or justification can be a locale-policy issue.
This JSON manifest-like file uses Chinese-only natural-language fields such as category, sub_category, and description. Under the stated policy, forcing a specific language without documented user opt-in can be a locale-policy violation unless the regional constraint is explicitly justified.
This JSON reference file uses Chinese-language category and description fields, and there is no surrounding natural-language indication that the skill is region-specific or that users can opt into this locale. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern even in config data.
This JSON reference file uses Chinese-language category and description fields and does not indicate that the locale is optional, user-selected, or limited to a China-specific deployment. Under the policy rule for language/locale, forcing a specific language without opt-in can be a natural-language policy violation.
The manifest context and file description indicate a focus on helping users understand indices and markets through technology-industry themed index data, yet entries such as '中证影视主题指数' and '中证娱乐主题指数' are categorized as '科技产业'. These themes are primarily entertainment/media and only weakly justified as technology-industry content, creating scope ambiguity in the dataset.
The description is written entirely in Chinese and provides no indication that other languages are supported or that the language choice is intentional and user-selectable. Under the policy, natural-language content that imposes a locale without opt-in can be a language/locale policy violation.
No suspicious patterns detected.