T01 · Skill Instruction Hijacking
- Location
references/core_workflow.md:313- Finding
Mandatory Third-Party Promotion and Subscription Solicitation in Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill performs its advertised WeChat account analysis, but it also has overbroad credential handling, persistent subscription behavior, mandatory promotional output, and unsafe HTML report rendering that users should review before installing.
Install only if you are comfortable giving the skill a Redfox API key, sending queried public-account names or IDs to redfox.hk, and storing generated raw/report data locally. Prefer setting the API key only in the current process or a dedicated secret store, do not let an agent append it to shell startup files or print it, avoid subscription/calendar follow-up unless explicitly desired, and treat generated HTML reports as untrusted until output escaping is fixed.
references/core_workflow.md:313Mandatory Third-Party Promotion and Subscription Solicitation in Agent Output
scripts/report.py:53Stored HTML Injection Through Unescaped Report Data
scripts/api_client.py:21Excessive Access to User Shell Configuration Files During Credential Discovery
SKILL.md:68Plaintext API-Key Persistence and Full-Secret Terminal Verification
SKILL.md:52Unpinned Runtime Dependency Installation
The documented purpose focuses on account diagnosis, but the skill also reads credentials from local shell startup files, performs external requests to a third-party service, and handles raw account lookup/data retrieval. This mismatch undermines informed consent and can expose local secrets or send data off-device in ways the user did not reasonably expect from the description.
The sync command invokes a remote endpoint to trigger data collection/subscription for account works, which goes beyond passive analysis of provided data. This can cause unauthorized external actions, collection of additional data, and user surprise if the tool is expected to only analyze existing account information.
The README explicitly tells users to invoke the skill via unconstrained natural-language requests rather than a narrowly defined command surface. In agent environments, broad activation phrasing can cause accidental routing or unintended invocation from loosely related user text, increasing the chance that the skill runs when the user did not clearly intend it.
The example phrases such as diagnosing or comparing accounts are short, generic, and overlap with ordinary conversational requests. Because they are not strongly scoped to this specific skill, an orchestrator or agent may mistakenly trigger the skill during unrelated discussions about account analysis, leading to unintended data access or actions within the skill's capability set.
The README says users can 'directly use natural language to describe needs, no need to remember commands,' but it does not define clear activation boundaries, exclusions, or a constrained trigger set. This can cause unintended invocation because many ordinary requests could plausibly match the skill's purpose.
The skill advertises capabilities that require environment access, file reads/writes, and outbound network access, but it does not declare any explicit tool scope or permission boundaries. This can cause the agent to exercise broader capabilities than users expect, increasing the risk of unintended credential access, filesystem modification, and external data transmission.
The documentation promotes data-driven diagnosis via a third-party API but does not clearly warn users that account-related queries and associated data will be sent to an external service. Lack of transparency around third-party data transfer reduces user awareness and may create privacy, compliance, or trust issues.
The skill instructs the agent to help persist API keys into shell configuration files, which creates long-lived secrets on disk and encourages the agent to modify sensitive startup files. This expands the blast radius of compromise, risks credential leakage through local file access, and may alter user environments in unexpected ways.
The trigger phrases are broad enough that normal conversation about account analysis may unintentionally activate the skill. Accidental activation is risky here because the skill can access credentials and initiate external API-driven analysis workflows without a clearly deliberate invocation.
The HTML document declares lang="zh-CN", which hard-codes a Chinese locale for the generated report. Under the policy, forcing a specific language or locale without user opt-in or a clearly documented region-specific justification is a natural-language policy violation.
The workflow requires users to provide a public-account name in Chinese and the rest of the file hard-codes Chinese-language greetings, templates, and output requirements. This imposes a language/locale constraint without opt-in or an explicit documented justification for limiting the skill to Chinese.
The manifest describes a tool that quantitatively scores a public account across four dimensions and outputs optimization suggestions. However, the workflow opening states it can analyze both operational data and '商业价值', and later the report mandates a subscription/tracking upsell flow for ongoing monitoring, which goes beyond one-off diagnostic scoring and advice.
The workflow sends user-supplied account identifiers and related query context to a third-party service without any user-facing disclosure or consent notice. Even if the queried data is public-account metadata, undisclosed transfer to an external provider introduces privacy, compliance, and trust risks, especially where user research targets or usage patterns may themselves be sensitive.
The workflow advertises a subscription/tracking capability that is not disclosed in the manifest, creating a hidden persistence or follow-up data-processing feature beyond the user's expected one-time diagnostic action. Undisclosed ongoing monitoring changes the privacy and consent profile of the skill and can lead to unexpected collection, retention, or repeated transmission of account-related query data.
The file prescribes a fixed '标准开场白' entirely in Chinese and presents it as required first-turn output. Because the guidance does not offer the user any language choice or state that the skill is limited to Chinese-speaking users for a documented regional reason, it creates a natural-language locale policy violation.
When an account is not found, the workflow instructs the agent to actively synchronize or collect data by calling an external interface with a user-supplied identifier. That exceeds a passive diagnostic scope and is risky because unverified user input is transmitted to a third party, potentially causing unintended data processing, privacy issues, or abuse of the sync endpoint.
The sync workflow sends account identifiers to an external API endpoint but provides no clear privacy or data-transmission warning. This is risky because even if the identifier is business-related rather than personal, transmitting user-supplied identifiers to a third party without transparent notice and consent can violate user expectations and organizational data-handling policies.
The workflow expands a passive account-analysis skill into persistent task scheduling and automatic future push behavior via calendar creation. This is dangerous because it creates stateful side effects and delayed actions outside the user’s immediate analysis request, which can surprise users, retain account identifiers longer than expected, and trigger follow-up actions without sufficiently explicit consent boundaries.
The subscription flow creates a calendar task and promises an automatic future push, but it does not clearly warn the user that account identifiers and task metadata will be stored for later execution. This is dangerous because users may consent to analysis without understanding the retention, automation, and follow-up processing involved, undermining informed consent and privacy expectations.
The document contains conflicting instructions for missing-account handling: one section says to ask the user to re-enter correct information, while the workflow elsewhere initiates sync and subscription actions. Such contradictions are dangerous because they make agent behavior unpredictable, increasing the chance of unauthorized external calls or task creation in scenarios where the safer behavior should be to stop and ask for corrected input.
The code persists full raw API responses and generated analysis reports to local JSON files in an output directory. If the queried account data includes identifiers, profile metadata, works, or similar-account information, this creates unnecessary at-rest retention and expands exposure beyond transient analytics behavior.
The code writes raw account data and analysis output to local files without any visible notice, consent flow, or retention disclosure in this file. Even if the data is not highly sensitive, silent persistence increases privacy and compliance risk because users may reasonably expect analysis to be in-memory only.
The query workflow sends account names and identifiers to remote APIs without any disclosure or visible consent mechanism in this code path. In an analytics tool this may be expected operationally, but undisclosed transmission still creates privacy and trust issues and may violate platform or organizational expectations.
The code enumerates and reads user shell startup files (.zshrc, .bashrc, .bash_profile, .profile) to extract an API key when the environment variable is absent. This expands the skill’s access to sensitive local configuration beyond what is necessary for a公众号 analysis tool, and can unintentionally expose unrelated secrets stored in those files or normalize secret harvesting behavior.
The fallback credential lookup reads sensitive shell configuration files without any user-facing notice, consent, or disclosure. Even if intended as convenience, silently accessing these files violates least surprise and can expose credentials or private configuration data from locations unrelated to the skill’s stated purpose.
No suspicious patterns detected.