T01 · Skill Instruction Hijacking
- Location
SKILL.md:18- Finding
Forced Verbatim Output Enables Agent Response Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Chinese rebate assistant, but it handles withdrawals and persistent account identifiers with under-disclosed privacy and control risks.
Review this skill carefully before installing. It is not obviously malicious, but it can access rebate account state, generate rebate links, and submit withdrawal requests after confirmation. Install only if you trust the rebate service endpoints and publisher, accept that WeChat/OpenID and shopping data may be stored locally and sent to remote services, and can tolerate the verbatim-output behavior.
SKILL.md:18Forced Verbatim Output Enables Agent Response Hijacking
scripts/m01OperationGuide.js:208Persistent WeChat OpenID Exposed in URL Query Strings
scripts/common.js:182Sensitive Identity and Withdrawal State Stored Without Explicit Restrictive Permissions
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
The documented trigger set and S01 description include operational account and withdrawal actions, but the static finding suggests the actual implementation may go further into balance lookup, rebate/order details, and real withdrawal execution without sufficiently prominent disclosure in the high-level purpose. Financially meaningful actions with incomplete declaration can mislead operators and increase the chance of unintended or unauthorized money movement.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
if (!state.requests || !state.requests[machineCode]) {
return;
}
delete state.requests[machineCode];
saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (modelValue && ruleValue) {
if (preferSpecific) {
if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
return ruleValue;
}
if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
return ruleValue;
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if (modelValue && ruleValue) {
if (preferSpecific) {
if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
return ruleValue;
}
if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
return ruleValue;
The skill exposes shell, network, and environment-backed capabilities through documented CLI scripts and API-dependent flows, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an avoidable over-privilege condition where the runtime may grant broader access than the narrowly described cashback workflows require, increasing blast radius if downstream scripts are compromised or misrouted.
Broad triggers like '返利', '教程', or balance/authorization phrases can cause accidental invocation from ordinary conversation, leading the skill to collect sensitive shopping/account context or initiate financial workflow steps unexpectedly. In a skill that can query balances and prepare withdrawals, overbroad invocation raises the risk of confused-deputy behavior and unintended state transitions.
The skill description and all trigger and response instructions are written exclusively in Chinese, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.
Routing based on simple keyword or URL presence without clear scope constraints can be abused or accidentally triggered by quoted text, pasted examples, or unrelated discussion. Because the skill routes into networked cashback/search/account flows, weak routing increases the chance of processing untrusted content as if it were an intentional financial or shopping request.
This file defines all routing inputs as Chinese-language phrases only, with no indication that users can choose another language or locale. Per the policy, forcing a specific language without documented opt-in or justification is a natural-language policy concern.
The generic JSON save helper performs filesystem writes, and it is used throughout this file to persist machine codes, auth state, OpenID bindings, and pending withdrawal/auth records. In this code file there is no confirmation prompt, user-facing log/print, or comment/docstring disclosing that such local state is being stored.
The manifest describes a rebate assistant with bounded user-facing scenarios, but this code adds a shell-level dependency by spawning curl for both rebate API access and arbitrary URL fetching. Subprocess execution is a stronger capability than ordinary HTTP requests and is not declared or obviously required by the manifest's functional description.
The manifest says the skill only works in three user scenarios: S01 authorization/tutorial, S02 link rebate, and S03 product search. This file implements a separate pending-withdraw request lifecycle with amount, openid, expiry, and confirmation state persisted locally, which is a substantive capability not reflected in the stated scenario boundaries.
This code loads model provider configuration from a local file and can send prompts to an arbitrary configured external LLM endpoint, which exceeds the stated rebate-assistant scope. In a skill that processes user messages and local identity/auth context, this creates a clear data exfiltration path to third-party services if configuration is changed or abused.
The code reads provider.apiKey from configuration and sends it in an Authorization header to an external model endpoint. There is no user-facing warning, logging, or explanatory comment here indicating that credentials are being used for an outbound API call.
The function sends system and user prompt content to a remote model provider, creating an external data transmission channel for user messages and potentially contextual internal data. In this skill, which handles identity-, auth-, and rebate-related workflows, undisclosed prompt export increases privacy and confidentiality risk.
This code sends HTTP/HTTPS requests to arbitrary URLs and can include caller-supplied headers and body data, which may transmit user or system data off-host. The file contains no confirmation prompt, logging, print statement, or explanatory comment/docstring disclosing that network transmission occurs.
This JavaScript file contains extensive user-facing instructional text entirely in Chinese, including onboarding, withdrawal guidance, and command phrasing such as replies the user should send. There is no indication that the skill offers language selection or that the Chinese-only locale is a documented, justified regional constraint, which conflicts with the policy against forcing a specific language without user opt-in.
No suspicious patterns detected.