T01 · Skill Instruction Hijacking
- Location
SKILL.md:106- Finding
Mandatory Commercial Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its bulletin-query purpose, but it needs review because it persists a membership token locally, can reveal part of that token, and forces subscription copy into user-facing answers.
Install only if you are comfortable with a local Bash script contacting ITjuzi, storing an ITjuzi Skill Token in your home directory, and adding subscription messaging to some answers. Prefer using the environment variable token path when possible, avoid running --show-token in logged sessions, and remove the saved token when it is no longer needed.
SKILL.md:106Mandatory Commercial Content Hijacks Agent Responses
scripts/telegraph_api.sh:40Bearer Token Prefix Disclosed by Token Status Command
scripts/telegraph_api.sh:54Unencoded Form Values Permit Request-Parameter Injection
The declared purpose is a bulletin-query skill, but the documented behavior includes persistent local token storage, token management commands, and authenticated remote API access that are not surfaced in the high-level description. This mismatch can mislead users and reviewers about sensitive behaviors, especially credential handling, and can result in users exposing or persisting secrets without informed consent.
The skill invokes shell scripts via bash/curl but does not declare any tool scope or permissions boundaries. That makes the skill's execution capabilities less transparent to the host and reviewers, increasing the risk of unintended command execution or over-broad access if the shell script behavior changes or is abused.
The skill instructs users to save a provided token permanently and says it will remain effective indefinitely, but gives no warning that the credential is being persisted locally. Storing authentication tokens without explicit consent, retention notice, or protection guidance increases the risk of credential theft from disk, accidental reuse, or exposure on shared systems.
The instructions require the assistant to append fixed Chinese-language text and explicitly forbid rewriting it. This imposes a specific language on the response without giving the user a language or locale choice, which is a natural-language policy concern.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/usr/bin/env bash
# IT桔子创投电报 API(v2)- 零依赖版本
# 仅使用 curl + bash 内置命令
set -euo pipefail
The skill implements token lifecycle commands for setting, removing, and inspecting credentials even though its stated purpose is only querying IT桔子 telegraph data. Expanding capability to credential management increases attack surface and creates opportunities for unnecessary secret handling, especially in agent contexts where users may not expect a query skill to persist or expose authentication state.
The script writes the bearer token to a persistent file under the user's home directory without any interface-level warning that a credential will be stored on disk. Silent persistence of secrets can violate user expectations and increases exposure through backups, filesystem access, or later reuse by other processes.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cmd_set_token() {
local token="$1"
mkdir -p "$TOKEN_DIR"
chmod 700 "$TOKEN_DIR"
printf '%s' "$token" > "$TOKEN_FILE"
chmod 600 "$TOKEN_FILE"
printf '{"success":true,"message":"Token saved to %s"}\n' "$TOKEN_FILE"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p "$TOKEN_DIR"
chmod 700 "$TOKEN_DIR"
printf '%s' "$token" > "$TOKEN_FILE"
chmod 600 "$TOKEN_FILE"
printf '{"success":true,"message":"Token saved to %s"}\n' "$TOKEN_FILE"
}
The --show-token command discloses credential metadata, including a 20-character token prefix, source, and storage path. Even partial secret disclosure can aid token guessing, correlation, phishing, or debugging abuse, and it is not justified by the skill's query-only purpose.
The query command sends keyword, event_type, pagination data, and optionally an Authorization bearer token to a remote HTTPS endpoint via curl. The script performs this network transmission without any user-facing notice, logging, or inline documentation warning that supplied inputs and credentials are sent to itjuzi.com.
This markdown file contains substantive user-facing content in Chinese, but it does not indicate that the skill is region-specific or provide any opt-in or language choice. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.
No suspicious patterns detected.