T01 · Skill Instruction Hijacking
- Location
SKILL.md:1325- Finding
Forced Promotional Output and Agent Response Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This stock-analysis skill is not clearly malicious, but it needs review because it stores and transmits API keys riskily and forces paid upgrade links into analysis output.
Install only if you are comfortable with a Chinese-language, freemium stock-analysis tool that creates a persistent local API key, contacts external market-data and payment services, and inserts upgrade links in preview reports. Avoid using a valuable paid key until the publisher uses HTTPS for all credential-bearing calls, narrows payment-token generation to explicit upgrade flows, and documents key storage and rotation clearly.
SKILL.md:1325Forced Promotional Output and Agent Response Hijacking
settings.json:2API Key Transmitted to the Default Analysis Service over Plaintext HTTP
ghdata/db_manager.py:23API Key Disclosed to a Separate Payment Domain Without User-Initiated Purchase Intent
ghdata/config.py:85Persistent API-Key File Is Created Without Explicit Restrictive Permissions
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
This variant goes beyond mere claim inflation by documenting reads and writes to a fixed credential file and auto-generation/persistence of API credentials, while presenting the skill mainly as an analysis tool. Hidden or under-emphasized credential lifecycle behavior can surprise users, create secret sprawl on disk, and expand the attack surface if local files are later exposed or mispermissioned.
The skill claims it does not generate conclusions, yet later mandates directional judgments, ratings, and conclusion text. This kind of contradictory instruction can mislead reviewers and users about the skill's real function, making risky decision-support behavior appear harmless and reducing informed consent around financially sensitive outputs.
The skill requests and documents capabilities for network access, local file read/write, and environment-variable access, but it does not declare an explicit tool scope or permissions block. That creates a governance gap: reviewers and runtime policy engines cannot easily constrain or audit what the skill is allowed to touch, increasing the chance of overbroad data access or unintended side effects.
The manifest description is written entirely in Chinese and presents the skill as operating in that language, with no indication that other languages are supported or that the user can choose a locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.
The manifest frames the skill as analysis/reporting, but the body also embeds conversion-focused payment-link generation and upsell behavior. Undeclared monetization flows can trick users into activating external purchase journeys they did not expect, and in agent ecosystems this can blur the line between analysis and commercial redirection.
Early compliance rules prohibit suggesting the tool recommends stocks, predicts price movement, or advises buy/sell/hold. Later preview templates include lines such as '现在该买还是该卖吗?' and other sales copy framing the hidden content as decision-making guidance. That contradicts the stated output restrictions rather than merely omitting nuance.
This section mandates specific Chinese replacements for output wording and translation rules for API fields, effectively constraining responses to Chinese phrasing. The file does not provide a user-facing option to select another language, so this constitutes a locale/language policy issue rather than a content-safety one.
The preview flow uses manipulative upsell language to steer users from neutral data viewing toward paid, more persuasive decision guidance. In a financial-analysis context, this increases the risk of coercive or misleading user influence, especially when mixed with claims of signal quality, historical match rates, and actionable guidance framing.
This Python file contains user-facing formatted output and CLI messages entirely in Chinese, including a docstring that says the formatter is for direct LLM output. Because the skill presents fixed-language output without any mechanism to let the user choose locale or opt in, it conflicts with the language/locale policy criteria.
The module title and primary user-facing documentation strings are entirely in Chinese, which imposes a specific language on users without any indication of locale choice. Under the stated policy, forcing a language without user opt-in is a natural-language policy violation.
The analyzer injects a payment/conversion URL into every analysis result, including when the caller only requested stock-analysis output. This creates a covert monetization/data-flow channel in a function that should return analytical data, and the hidden side effect could mislead downstream agents or users into surfacing promotional or tracking links unexpectedly.
Checking payment status and generating payment links inside the core analysis routine mixes unrelated business logic into a data-analysis function. In an agent setting, this can become a deceptive capability escalation: a caller asking for stock insights also triggers monetization behavior and receives payment artifacts that may encode identity or account state.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
groups[p['pattern_type']].append(p)
summary = []
for idx, (ptype, plist) in enumerate(sorted(groups.items()), 1):
plist_sorted = sorted(plist, key=lambda x: x['created_at'] or '', reverse=True)
latest_p = plist_sorted[0]
verify_count = len(plist_sorted)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
groups[p['pattern_type']].append(p)
summary = []
for idx, (ptype, plist) in enumerate(sorted(groups.items()), 1):
plist_sorted = sorted(plist, key=lambda x: x['created_at'] or '', reverse=True)
latest_p = plist_sorted[0]
verify_count = len(plist_sorted)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
groups[p['pattern_type']].append(p)
summary = []
for idx, (ptype, plist) in enumerate(sorted(groups.items()), 1):
plist_sorted = sorted(plist, key=lambda x: x['created_at'] or '', reverse=True)
latest_p = plist_sorted[0]
verify_count = len(plist_sorted)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
groups[p['pattern_type']].append(p)
summary = []
for idx, (ptype, plist) in enumerate(sorted(groups.items()), 1):
plist_sorted = sorted(plist, key=lambda x: x['created_at'] or '', reverse=True)
latest_p = plist_sorted[0]
verify_count = len(plist_sorted)
The module title, comments, docstrings, and font settings are explicitly tailored to Chinese usage, including SimHei, Microsoft YaHei, and Noto Sans SC. This indicates a Chinese locale assumption in the skill behavior without offering a language choice or documenting that the skill is intentionally region-specific.
The module is presented as a chart-rendering utility, but the exported generate() function performs an undisclosed network fetch to Tencent API before rendering. In agent environments, hidden outbound network access can violate least-surprise and data-flow expectations, expanding the trust boundary and creating privacy, compliance, or supply-chain risk if callers assume the function is purely local/offline.
Detected: suspicious.exposed_secret_literal