T01 · Skill Instruction Hijacking
- Location
SKILL.md:226- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Yoinkit appears to be a coherent social-media research API wrapper, but it needs Review because it sends tokens and research inputs to a configurable remote endpoint and includes extra response-branding and scheduled workflow behavior.
Install only if you are comfortable sending social URLs, handles, search topics, transcripts, and related metadata to Yoinkit. Keep `YOINKIT_API_URL` on the default HTTPS Yoinkit endpoint unless you intentionally use a trusted local server, and use a separate development token for local testing. Review optional cron examples before enabling them, especially the Obsidian workflows that overwrite notes, and pin or verify the installer where possible.
SKILL.md:226Mandatory Promotional Content Hijacks Agent Responses
scripts/content.sh:20Configurable API Base URL Can Expose the Bearer Token to an Untrusted or Plaintext Endpoint
README.md:20Installation Executes an Unpinned Registry Package
The declared description presents a broad social-platform research capability: searching, analysis, transcription, trending-topic retrieval, and metadata workflows across 13 platforms. The supplied code chunk is much narrower. It only validates inputs and calls platform-specific API endpoints to retrieve a user's recent posts/videos feed for 8 platforms (YouTube, TikTok, Instagram, Twitter, Facebook, Threads, Bluesky, Truth Social). There is no code for search, transcript generation, content analysis, trending-topic collection, or orchestration of research workflows. This is a material description-to-behavior mismatch because the actual primary purpose is user feed retrieval, not the broader declared capabilities.
The description overstates the implemented scope. The script does support multi-platform research behavior, including search, trending, and optional transcript retrieval, so it is related to the declared purpose. However, it does not match the claimed breadth: it does not cover 13 platforms, trending is limited to YouTube and TikTok, search is limited to five named platforms, and transcript collection in this code path is only performed from extracted trending URLs for supported platforms. It also does not implement meaningful analysis functionality beyond aggregating API responses. Therefore the description is not an accurate representation of the actual code behavior.
The declared description substantially overstates the implemented functionality. This shell script is narrowly focused on searching a single specified platform through an external API endpoint. It validates one of five supported platforms, accepts a query and optional pagination/sorting parameters, performs a curl request, and prints the API response. There is no evidence in this code chunk of transcript generation, content analysis, trending-topic discovery, support for 13 platforms, or cross-platform workflow features. Therefore the description does not accurately represent the behavior shown.
The code chunk is narrowly focused on one function: given a URL, detect a supported platform, call a transcript endpoint, and print transcript text. It does not perform search, trend discovery, content analysis, metadata collection, or any broader research workflow orchestration described in the declaration. It also supports only five platform families in this code path, not 13. While transcript extraction is part of the declared description, the overall declared purpose materially overstates the implemented functionality, so this is a description/behavior mismatch.
The description significantly overstates the skill's scope and capabilities. The code chunk is narrowly focused on a trending endpoint wrapper for two platforms, validating the platform, parsing a few options, calling the Yoinkit API, and printing JSON results. It does not implement content search across many platforms, transcript extraction, analysis, or broader research workflows. This is a material description-behavior mismatch because the declared primary purpose is much broader than the actual implemented functionality.
The README promotes automated cross-platform scraping, transcript extraction, feed monitoring, and scheduled research collection across multiple social platforms, but provides no guidance on privacy, consent, retention, or platform Terms-of-Service constraints. In this context, the omission matters because the skill is explicitly designed for recurring large-scale collection workflows, which increases the chance of collecting personal data or sensitive content without appropriate safeguards.
The README instructs users to install via npx clawhub install yoinkit without pinning a specific package version or integrity mechanism. This creates a supply-chain risk: users may fetch whatever version is current at install time, and if the upstream package or distribution channel is compromised, a malicious release could be executed during installation.
The skill documents shell-style commands and appears to rely on command execution, but it declares no explicit tool scope or allowed-tools restrictions. In an agent environment, missing tool scoping increases the chance the skill can invoke broader shell capabilities than intended, making misuse or prompt-driven command execution harder to contain.
The skill states that all requests go through a remote Yoinkit API and handles transcripts, content, search queries, and research workflows, but it does not clearly warn users that URLs, queries, and retrieved social content may be transmitted to a third-party service. This creates a meaningful privacy and data-governance risk, especially if users submit sensitive research topics, private links, or regulated content under the assumption processing is local.
The scheduled agent is instructed to modify and overwrite an existing Obsidian note in place, but the workflow provides no user-facing warning, confirmation step, or backup mechanism before saving changes. Because this runs automatically at 8 AM and processes multiple entries, mistakes in transcript retrieval, summarization, or note targeting could silently alter or corrupt user-authored research notes.
The script sends the user-supplied topic to a third-party API for search and later sends derived content URLs for transcript retrieval, but it provides no runtime notice, consent prompt, or data-minimization control. In a research skill, users may enter sensitive queries or investigate confidential subjects, so silent transmission to an external service creates a meaningful privacy and data-governance risk.
This imposes a fixed locale on results, which is a natural-language policy issue because the skill forces a specific region without user opt-in. Nothing in the surrounding usage or comments indicates that the skill is intentionally US-only or allows the user to select another locale.
The script transmits the user-supplied video URL to an external Yoinkit API service using an authenticated request, but it provides no explicit user-facing disclosure at runtime that the URL and associated metadata will leave the local environment. This can expose sensitive or private links, especially in enterprise or research workflows where users may assume local-only processing from the command name and transcript-focused behavior.
The manifest hard-codes the schedule time zone to "America/Chicago," which imposes a locale-specific behavior. There is no indication that this locale choice is optional, user-selected, or justified as a region-specific skill requirement.
This manifest describes the skill as scanning feeds, trending content, and saving notes, but it does not define any explicit scope boundaries or exclusion conditions for what counts as relevant content. In a manifest file, that lack of specificity can make the activation/behavior description overly broad and prone to unintended collection beyond the intended research domain.
The manifest fixes execution to the America/Chicago time zone, which imposes a locale-specific behavior in the skill configuration. The file does not indicate that the user chose this locale or that the constraint is required for a region-specific purpose.
No suspicious patterns detected.