T01 · Skill Instruction Hijacking
- Location
SKILL.md:132- Finding
Mandatory Response Hijacking and Promotional Content Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its social-media research purpose, but it automatically sends queries to external services and opens locally generated HTML that is not safely sanitized.
Review before installing. Use this only for topics you are comfortable sending to WebSearch and RedFox, avoid confidential brand/customer/investigation terms, and prefer not to open generated HTML automatically until the report generator escapes content and validates links. Configure a revocable RedFox API key and watch where reports are saved.
SKILL.md:132Mandatory Response Hijacking and Promotional Content Injection
scripts/cn_last30days.py:506Stored HTML and Attribute Injection in Automatically Opened Reports
Enabling implicit invocation without precise activation constraints makes it likely the skill will auto-trigger based on loosely related phrases, causing the system to perform cross-platform social-media analysis when the user did not clearly request it. In this context, the skill targets real discussions on major Chinese platforms, so accidental activation can lead to unnecessary handling of sensitive reputational, political, or personal-topic research and increase privacy, compliance, and misuse risks.
The script accesses environment variables and local configuration files to obtain API credentials, but that capability is not reflected in the declared skill behavior. In an agent setting, undeclared access to ambient credentials expands the trust boundary and can surprise users who expect a search-only tool.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
</div>'
)
xhs_notice = (
'<div style="background:#fff3cd;border:1px solid #ffc107;border-radius:8px;padding:10px 14px;margin-bottom:14px;color:#664d03;font-size:13px;line-height:1.6">'
'⚠️ 受小红书风控规则限制,部分作品链接可能无法正常跳转,您可复制对应作品标题前往小红书搜索查看,感谢理解🙇♀️🙇♀️'
'</div>'
) if pkey == "xhs" else ""
no_data_html = "<div class='no-data-hint'><p>未查询到相关内容,建议更换关键词重试。</p></div>" if not items else ""
panels_html += (
'\n <div class="tab-panel" id="panel-' + pkey + '" style="display: ' + display + '">\n'
' ' + error_html + '\n'
' ' + xhs_notice + '\n'
' <div class="card-list">\n'
' ' + cards + '\n'
' </div>\n'
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Highlights
- **Pre-research mechanism**: Automatically runs WebSearch to extract trending terms before calling the engine, optimizing query strategy.
- **Smart merging**: Automatically merges related keywords into a single call to reduce API invocations.
- **Signal interpretation**: Automatic interpretation of key metrics like Xiaohongshu save/like ratio, Douyin share count, and WeChat read count.
The README states that the skill automatically runs WebSearch and generates reports, but it does not warn users that their prompts, derived keywords, and possibly research targets may be transmitted to external services and persisted in output artifacts. In a social-media research context, this can leak sensitive topics, internal brand-monitoring objectives, or regulated data to third parties without explicit consent.
The README explicitly advertises a built-in free public API key, which normalizes shared credential use and implies the skill may embed reusable third-party access. Even if the key is low-privilege, public/shared credentials enable abuse, quota exhaustion, attribution problems, and can expose users to an untrusted external service without informed consent.
The documentation gives conflicting security guidance by claiming the skill ships with a built-in public key while also warning users not to hard-code or expose keys. This contradiction can mislead users and reviewers about actual secret-handling practices, increasing the chance of insecure deployment, accidental credential disclosure, and unsafe trust in embedded access.
The README says users can 'Simply describe the topic you want to research in natural language—no fixed commands to memorize,' then gives broad everyday-style example phrases such as 'Research AI video tools for me' and 'Compare the reputation of Product A and Product B.' This leaves activation scope underspecified and increases the chance of unintended invocation from ordinary conversational requests.
The README instructs users to invoke the skill with very broad natural-language phrases such as generic research or trend-analysis requests, without clearly delimiting when this skill should activate versus when a normal conversation should continue. In an agentic environment, this can cause unintended tool invocation on loosely related prompts, potentially sending user queries to external social-media research services and expanding data exposure beyond user intent.
The skill explicitly instructs the agent to automatically generate an HTML file, write it to disk, and open it locally without asking the user first. This creates an unsafe side effect boundary: even if the HTML is locally generated, it may contain untrusted content derived from external data sources, and auto-launching it can surprise the user, trigger browser execution of active content, or expose local environment behavior without consent.
The skill description and default prompt are broadly phrased to research 'any topic' across major Chinese social platforms, but they do not define clear scope, safety boundaries, or activation criteria. This increases the chance of over-broad triggering and use on sensitive subjects, enabling unintended collection, summarization, or amplification of contentious social or reputational content without sufficient user intent verification.
The file requires the assistant to always begin with a Chinese-language badge and continue with a Chinese-only output template, without considering the user's preferred language. This can cause unauthorized language steering, degrade usability, and mislead users who expect answers in another language, especially in multilingual or accessibility-sensitive contexts.
The rule enforces fixed Chinese phrasing and response structure for general queries, leaving no option to adapt to the user's language or communication needs. In a user-facing research skill, this creates a systematic policy-quality issue by overriding user intent and potentially reducing transparency and trust.
The skill reads secrets from REDFOX_API_KEY/X_API_KEY and from ~/.qoder/apis/redfox.json, which goes beyond a purely topical research function and relies on ambient credentials. This is dangerous in agent environments because a caller may trigger credential use without realizing the tool will inspect host secrets.
The tool sends the user-provided keyword and source metadata to an external service at redfox.hk. If users enter confidential brand, customer, incident, or investigation terms, those sensitive queries are disclosed to a third party without an explicit runtime warning or consent step.
The generated report explicitly declares zh-CN and all visible interface text is fixed in Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the restriction is clearly documented and justified.
In from-json mode, the script creates an output directory and writes an HTML file to disk. Persistent writes are a real side effect that exceeds a narrow 'analysis' expectation and may expose searched topics or generated reports on shared systems.
Normal execution persistently saves JSON and/or HTML reports under the user's Downloads-derived directory. This can leak potentially sensitive research topics or collected content into a broadly accessible location without strong user awareness.
Advertising automatic daily updates without warning about recurring external access and ongoing report/output generation creates a transparency and privacy risk. Users may unknowingly authorize repeated data transmission, repeated scraping/search activity, or accumulation of generated files that reveal their monitoring interests over time.
The manifest description is entirely in Chinese and frames the skill for Chinese-language use without indicating any option for the user to choose another language. Under the policy for natural-language constraints, forcing a specific language without opt-in can be a locale/language policy issue unless explicitly justified.
The operational instructions and output requirements are presented only in Chinese, and no opt-in or language-selection mechanism is described. Because the skill is user-invocable, this can amount to forcing a specific language/locale experience without giving the user a choice.
This function accesses REDFOX_API_KEY and X_API_KEY from the environment and also reads a local credential file under ~/.qoder/apis/redfox.json. Although this is functionally necessary, the file does not clearly disclose to users that it will inspect those credential sources.
This path creates directories and writes HTML output, and similar write behavior also appears later for JSON and HTML exports. The code reports successful saves after writing, but it does not warn up front that running the tool will create files under ~/Downloads/CnLast30Days by default.
No suspicious patterns detected.