T01 · Skill Instruction Hijacking
- Location
SKILL.md:20- Finding
Forced Promotional Output and Agent Response Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This rebate assistant is not clearly malicious, but it should be reviewed because it can access account data and submit withdrawal requests with broad routing, verbatim output rules, and local sensitive-state storage.
Install only if you trust the rebate backend and hardcoded WeChat/public-account URLs. Be aware that the skill can store OpenID, shopping requests, balances, and pending withdrawal data locally, can use your configured model API key for search-intent parsing, and can submit a withdrawal after an amount is prepared and the user replies with a confirmation phrase.
SKILL.md:20Forced Promotional Output and Agent Response Hijacking
scripts/common.js:185Sensitive Account and User State Stored Without Restrictive File Permissions
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
The code can submit real withdrawal requests via applyWithdraw(openId, amount) after only conversational flow state and a pending request check. Because this is a real financial action outside the narrow declared purpose of authorization/tutorial, link rebate, and search, it increases the chance of unauthorized or unexpected money movement if the intent classification, local state, or calling context is abused.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (modelValue && ruleValue) {
if (preferSpecific) {
if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
return ruleValue;
}
if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
return ruleValue;
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (modelValue && ruleValue) {
if (preferSpecific) {
if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
return ruleValue;
}
if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
return ruleValue;
The skill declares executable scripts with shell, network, and environment access, but the manifest/documentation does not define an explicit tool scope such as allowed-tools or permissions. That makes the effective capability boundary opaque to reviewers and increases the risk of unintended command execution, data access, or outbound requests if the runtime grants broad defaults.
Using broad everyday trigger terms like “教程” and “账户余额” can cause accidental activation of the rebate skill or sensitive account flows from messages that were not intended for this skill. In a system that can expose account information or initiate withdrawal preparation, overbroad triggers increase the chance of unintended data access or action routing.
The manifest description and examples are written as if the skill operates only in Chinese, and the document provides no opt-in or alternative language handling. A skill that effectively forces a specific language without user choice can violate language/locale policy requirements.
The routing rule 'no link + shopping intent => S03' is vague and may over-capture normal conversation into product-search behavior. While lower risk than financial-action misrouting, ambiguous routing can still send unintended user text to downstream search or external APIs, creating privacy and consent concerns.
The file contains natural-language user-facing strings in Chinese, and similar Chinese-only messages appear throughout the module. This forces a specific language/locale without any visible opt-in or fallback, which matches the language-policy violation criteria.
The manifest says the skill only works in three user scenarios: S01 authorization/tutorial, S02 link rebate, and S03 product search, with S03 limited to extracting search info and returning results. This file implements explicit pending-withdraw request creation, loading, expiry, and clearing, which is a distinct提现 transaction workflow rather than merely tutorial or search support.
This utility file loads global model-provider configuration, including base URL and API key, and can make arbitrary chat completion requests. For a rebate assistant whose stated purpose is authorization, rebate-link handling, and product search, access to unrelated workspace-wide LLM credentials expands the skill's privileges and creates a pathway for secret use or exfiltration if any caller can influence prompts or trigger these functions.
This code reads a configured model API key and uses it in an outbound HTTP Authorization header, which is a sensitive-credential access plus network transmission path. In this file there is no confirmation prompt, user-facing log/print, or comment/docstring warning that the skill will use stored credentials to contact an external model endpoint.
User-facing strings throughout the file are written exclusively in Chinese, including tutorials, prompts, and status messages. This enforces a specific language experience without any visible opt-in, fallback, or documented regional justification in the file.
The skill implements additional sensitive capabilities—account balance lookup, rebate detail retrieval, and withdrawal handling—that are not clearly declared in the stated three-scenario scope. This creates a scope/permission mismatch: users, reviewers, or policy gates may believe the skill only provides tutorial, link conversion, and product search, while the code can trigger financial-account workflows and expose account-linked data.
The withdrawal is executed after a generic '确认提现' confirmation, but the user-facing flow does not present a strong warning that this is a real financial operation, may be irreversible once submitted, and will transfer funds based on previously stored state. In chat-driven systems, terse confirmations are error-prone and can be triggered accidentally or via confusing context, increasing the risk of unintended withdrawals.
The embedded system prompt is entirely in Chinese and instructs the model in a fixed language/locale, with no indication that the user can choose another language. This can violate language/locale policy when the skill is expected to adapt to user preference unless the restriction is explicitly justified.
No suspicious patterns detected.