T01 · Skill Instruction Hijacking
- Location
SKILL-execution.md:13- Finding
Agent Session Hijacking and Persistent Workflow Control
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches a report-generation purpose, but it gives itself broad automatic control, persistent workflow state, and risky file/rendering behavior that users should review before installing.
Install only if you are comfortable with an autonomous report workflow that writes many files into `.agent/harness/`, resumes from saved state, and may render spreadsheet-derived content into HTML/PDF. Review generated reports before sharing them, avoid sensitive spreadsheets unless masking is verified independently, and restrict output paths to a dedicated project folder.
SKILL-execution.md:13Agent Session Hijacking and Persistent Workflow Control
conspect_tools/run.py:1025Arbitrary File Write Through Unrestricted Output Paths and Filenames
conspect_tools/render_engine.py:465Stored Script Injection in Generated Dashboards
{description}
' if description else ''} """ ``` ```python cards += f"""conspect_tools/report_renderer.py:55Unsafe Report HTML Is Executed in a Headless Browser
conspect_tools/run.py:140Sensitive Data Is Returned and Rendered Without the Documented Masking Controls
conspect_tools/render_engine.py:575Generated Offline Reports Execute an Unpinned Remote JavaScript Dependency
该代码片段的职责非常窄,核心是对传入数据字典做特征提取和基础统计,属于分析流水线中的一个底层模块。文件注释和类文档都明确写明“只负责提取数据特征,不负责图表选型决策”,这与声明中“AI自动完成数据解析、图表选型、商务排版、可视化渲染,输出专业报表”的完整产品能力明显不一致。代码中也没有看到Excel文件处理、多表合并、报表生成、图表渲染、投屏输出等相关实现。因此这不是轻微的实现细节差异,而是声明描述了一个完整自动化报表系统,而代码实际只是其中一个支持性子模块,主用途存在实质性偏差。
声明描述的是完整的智能报表生成产品,核心能力应包括自动图表选择、报表布局、视觉渲染和最终报告产出。而提供的代码仅覆盖数据读取和基础分析层:用 pandas/openpyxl 读取 Excel,返回 sheet 结构,进行去重/填充,按列类型识别时间/分类/数值维度,做 sum/avg/max/min/count 聚合和分组汇总,并生成非常基础的 insights 文本。虽然这些功能与“数据解析、多表分析”部分有关,属于支持性子能力,但距离声明中的主要能力——自动生成专业商务报表并完成可视化呈现——差距明显。因此描述显著夸大了代码实际行为,构成实质性不匹配。
The declared description promises a comprehensive automated reporting product: ingesting Excel, performing AI analysis, selecting charts, producing business-formatted visual reports, and outputting presentation-ready deliverables. The supplied code does something much narrower and different: it defines a DataStatistics class for core statistical calculations such as mean/median/std, concentration ratios, trend metrics, distribution characteristics, anomaly detection, and correlation. The module docstring explicitly says it only handles basic statistical computation and not insight generation or decision-making. There is no file handling, Excel processing, charting, rendering, templating, report generation, dashboard production, multi-table merging, or autonomous workflow management. This is therefore a clear description-behavior mismatch, with the code representing only a small analytical support component rather than the declared full automated reporting tool.
The declared description promises an end-to-end intelligent analytics/reporting system centered on Excel ingestion, automatic analysis, visualization selection, business formatting, and final report generation. However, the supplied code chunk does not perform data ingestion, analysis, charting, rendering, or AI orchestration. Its actual purpose is much narrower: exporting provided content to files in several formats, saving an index, and duplicating files with Chinese names. While export could be a supporting component of a larger reporting system, this chunk by itself materially differs from the declared primary purpose and mainly implements an undeclared exporter module rather than the advertised autonomous analytics workflow.
描述强调的是一个端到端、全自动的 AI 数据分析与商务报表生成工具,核心能力应包括数据源接入(尤其Excel)、自动解析、多表合并、智能分析、图表选型和最终渲染。当前代码片段仅覆盖最后一环:把外部已整理好的 layout/data 渲染成 HTML 看板,并附带简单的主题、样式、交互和表格展示功能。虽然这与“商务报表渲染”部分一致,但与声明中的主要价值主张——自动数据分析与全流程托管——存在明显落差,因此属于描述与实际行为不匹配。
声明描述的是一个端到端的“数据智能分析+商务报表自动生成”系统,重点在于数据摄取、解析、分析、图表选型和全流程自动产出。实际代码则只接收一个已经准备好的 report_design 结构,并将其渲染成多种文档格式。代码中没有任何 Excel 处理、数据清洗、多源合并、AI 推理、图表生成或分析决策逻辑。虽然“商务报表渲染”这一子能力与声明部分吻合,但该代码块体现的主要职责仅是最终展示/导出层,显著窄于声明的核心能力,因此属于描述与行为不一致。
The declared description promises an end-to-end AI business reporting system: ingesting Excel, automatically analyzing data, selecting chart types, laying out business reports, rendering visualizations, and producing ready-to-present outputs without user confirmation. The supplied code does something much narrower and materially different. It defines a ReviewDataLoader whose documented role is only to load audit/review data and perform simple comparisons. It reads JSON and text files from disk, returns context dictionaries, extracts existing chart/color/layout fields, and compares numeric values or dict fields for consistency. There is no Excel handling, no AI orchestration, no autonomous chart selection, no report rendering, no dashboard generation, and no final output production. This is a clear description-behavior mismatch in primary purpose and advertised capabilities.
声明描述聚焦于 Excel 数据自动分析、图表选型、商务排版和报表/看板渲染,这与代码中的分析、统计、图表、洞察、渲染、保存等部分基本一致。但该代码块还明显实现了一整套额外的审核/质检工作流:review_design、review_implement、verify_end_to_end、final_judgment、generate_review_report、load_review_context,以及 compare_data 等。这些功能更像项目质量审计/评审工具,而不是单纯的商务报表自动生成器,属于未声明的重要能力扩展。另一个偏差是,描述强调“全流程托管AI自动生成,零用户确认环节”,而代码实际提供的是一个多 action 的通用 CLI,很多步骤需要显式调用不同动作来完成,并没有在该入口中体现一个单一的、完全自动的端到端流水线。因此描述不能完整且准确代表实际代码行为,应判定为不匹配。
The declared description presents a complete production skill for automatic Excel-based multi-source analysis and polished report rendering. However, the provided code is only a test module (tests/test_ai_agent.py) validating data classes and several AI-agent decision methods such as chart choice, insight generation, and review checks. While chart selection and insight generation are loosely related to the description, the primary purpose of this code chunk is software testing, not executing the advertised workflow. There is no evidence here of file ingestion, Excel parsing, multi-table consolidation, visualization rendering, business formatting, or presentation-ready report export. Therefore the description materially overstates and misrepresents what this supplied code chunk actually does.
The declared description presents a complete automated reporting product with Excel ingestion, intelligent analysis, charting, visual rendering, and polished business-report output. The supplied code chunk does not implement that workflow. It is a test module validating a narrow helper/component behavior: extracting basic structural features from provided data dictionaries. While such feature extraction could be a supporting internal detail of a larger analytics system, this code chunk by itself materially differs from the declared primary purpose and lacks the major advertised capabilities. Therefore this is a description-behavior mismatch.
The declared description promises a comprehensive automated reporting product focused on Excel/multi-source ingestion, AI analysis, charting, business formatting, and final rendered reports. The actual code provided is only a unit test module for a statistical helper class. Its observable behavior is limited to validating numerical/statistical functions such as totals, averages, concentration, trends, distributions, and anomaly detection. This is materially different from the declared primary purpose and lacks the core advertised capabilities, so the description does not accurately represent the supplied code chunk.
The declared description promises a broad end-to-end AI analytics product: ingesting Excel and multiple data sources, automatically analyzing data, selecting charts, composing business layouts, and rendering polished reports with no user interaction. However, the provided code chunk only contains tests for a report renderer component. The tests pass in manually constructed report_design dictionaries and verify output files for Markdown/HTML, with minimal interface checks for PDF/Word. This behavior is much narrower and centered on rendering formatted output from an existing design, not on automated data ingestion, AI analysis, chart recommendation, or multi-source/table analysis. Therefore the supplied code does not accurately represent the declared full-purpose skill.
The declared description promises an end-to-end automated Excel-based intelligent analysis and report-rendering system. The actual code chunk does not implement or even directly invoke such functionality; it is a unit test module for a ReviewDataLoader. Its behaviors are limited to loading JSON-based context/chart data, comparing dictionaries for consistency, and extracting chart/color metadata. That is materially different from the declared primary purpose and omits the headline capabilities (Excel upload, AI analysis, chart choice, report composition, visual rendering/output).
The skill activates on broad generic intent like data analysis or report generation, then mandates immediate execution. In a file-writing, autonomous workflow, such loose triggering can cause unintended activation and automatic processing of user files or project data without a deliberate opt-in.
The skill requires automatic creation of baton, analysis, QA, report, and other files, and says execution must begin immediately without waiting for extra user instruction. Silent or insufficiently disclosed file generation is dangerous because it creates persistent side effects, may overwrite expectations about workspace cleanliness, and can expose sensitive derived data into predictable local paths.
The document states that the agent must not write custom HTML/CSS/JS rendering logic and must rely on RenderEngine, but later sections instruct the agent to generate HTML skeletons, inject CSS/JS, and inline chart code. This contradiction weakens safety boundaries, making it easier for an agent to justify arbitrary code generation outside the intended controlled rendering path.
The file claims all rendering and file operations must go through the CLI layer, but later directs direct execution of a Python HTTP server and OS-level process termination. This inconsistency undermines the control boundary of the CLI and permits unmanaged process execution, which can lead to persistent background services, unintended network exposure, or unsafe shell/process behavior.
export_pdf 和 export_png 的注释声称分别“导出PDF”和“导出PNG”,但实际实现仅执行 html.encode('utf-8'),返回的是原始 HTML 文本字节,而不是 PDF/PNG 格式内容。这不是简单的未实现细节,而是接口语义与代码行为直接冲突。
The protocol explicitly removes user confirmation and mandates automatic progression across analysis, design, implementation, and report generation. In a skill that ingests user-supplied Excel data and autonomously produces deliverables, eliminating human approval creates a meaningful risk of unauthorized actions, misinterpretation of sensitive data, or generation of misleading outputs without a stop point.
The change note normalizes zero user confirmation without any compensating safety warning or control requirements. In this context, the skill is designed for end-to-end automated business reporting, so silent progression can propagate data quality errors, privacy issues, or unsafe conclusions directly into polished outputs that users may trust and present externally.
The manifest explicitly advertises fully automated processing of uploaded Excel data and rendered report generation with 'zero user confirmation,' but it provides no warning, consent boundary, or description of how uploaded data is handled. In a data-analysis skill, this increases the risk of unintended processing of sensitive spreadsheet contents, surprising actions, or silent generation/output behavior without meaningful user review.
The manifest sets language: zh-CN, which appears to impose a single language/locale. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.
The changelog explicitly documents removal of the user confirmation step and emphasizes fully automatic progression with zero user confirmation. In a skill that ingests uploaded Excel data and automatically generates business reports, eliminating human approval increases the risk of unreviewed analysis, misleading output, unintended disclosure in rendered reports, and unsafe autonomous actions without an explicit warning or consent boundary.
The README explicitly advertises a zero-confirmation, fully automated workflow and elsewhere states that artifacts are written into the project workspace under .agent/harness/. In an agent environment, automatic file creation without an explicit warning or confirmation increases the risk of unintended overwrites, leakage into shared workspaces, and surprising side effects from a simple natural-language trigger.
The skill mandates immediate creation and repeated modification of files under {项目路径}/.agent/harness/ before doing substantive work and without user-facing consent. Silent writes into the user's project can overwrite expectations, create persistence artifacts, and violate trust boundaries, especially when activation alone triggers the behavior.
No suspicious patterns detected.