T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:123- Finding
Delegated Sub-Agent Can Send Unreviewed Task Results to External Messaging Channels
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent sub-agent orchestration protocol, but it gives delegated agents under-scoped authority to send task results to WeChat or Telegram without final user review.
Review this skill before installing if your delegated tasks may include private messages, source code, credentials, business data, or personal information. It should only be used where external notification destinations are explicitly approved and where sub-agents are not allowed to send sensitive content without main-session review.
SKILL.md:123Delegated Sub-Agent Can Send Unreviewed Task Results to External Messaging Channels
The skill instructions are written entirely in Chinese and implicitly require operation in that language, but there is no opt-in, language selection, or justification that this is a region-specific skill. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation.
This section instructs a spawned sub-session to dynamically read skills/<skill-name>/SKILL.md, where skill-name is supplied through the routine payload. Without an allowlist, path validation, or capability boundary checks, this creates a genuine skill-enumeration and potentially unauthorized skill-loading risk, allowing a caller to probe available skills or induce loading of unintended internal skill definitions.
收到 [ROUTINE]
→ 读 skills/subagent-orchestrator/SKILL.md(本文件)
→ 读 skills/<skill-name>/SKILL.md(任务技能)
→ 分析任务 → 拆解 checklist
→ 在工作区创建 task.md
This protocol explicitly instructs sub-sessions to create and update workspace files and, in some cases, directly send results to external channels like WeChat or Telegram. Because it does not require explicit user confirmation, data classification, destination validation, or safety warnings before writing or transmitting content, it creates a real risk of unintended data modification or exfiltration, especially when the sub-agent handles sensitive task material.
The protocol is written entirely in Chinese and includes Chinese-only field names and examples, which can amount to a forced language/locale constraint if this is the operative skill instruction set. The file does not indicate that users may choose another language or that the Chinese-only requirement is a documented, justified regional constraint.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
[ROUTINE]
协议: skills/subagent-orchestrator/SKILL.md
技能: <skill-name>
工作空间: workspace/<task-id>/
通知用户: true/false
The protocol explicitly allows a sub-session to send results directly to external channels such as WeChat or Telegram, even though the skill’s stated purpose is orchestration and collaboration. This expands the trust boundary and creates a data exfiltration/privacy risk, especially because delegated tasks may contain sensitive user content and the document does not define strict consent, scoping, or approval controls for external transmission.
The document describes sending task results to external messaging platforms but does not require any user-visible warning about data leaving the local/session environment. Users may reasonably assume outputs stay within the agent system, so silent transmission to third-party channels can violate privacy expectations and potentially disclose confidential information.
The template is entirely written in Chinese and implicitly steers generated retrospective content into Chinese without any user choice or opt-in. In a subagent orchestration skill, this can cause instruction-language mismatch, reduce transparency for users expecting another language, and lead delegated agents to produce inaccessible or policy-misaligned outputs.
No suspicious patterns detected.