T01 · Skill Instruction Hijacking
- Location
assets/skill-templates/tool-wrapper.md:54- Finding
Loaded reference files are granted unsafe instruction precedence
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill broadly matches its stated trading-strategy factory purpose, but it needs Review because it can drive live trading, VPS deployment, and GitHub publishing with sensitive credentials and limited explicit pre-action controls.
Install only in an isolated development workspace, not near production credentials or funded wallets. Pin installer versions, use least-privilege OKX keys and a limited test wallet, require explicit confirmation before any signing, VPS deployment, git push, or GitHub release, and audit generated skills before use, especially any reference files treated as authoritative.
assets/skill-templates/tool-wrapper.md:54Loaded reference files are granted unsafe instruction precedence
assets/publish.sh:53Unvalidated strategy identifiers permit filesystem path traversal
README.md:42Installation instructions execute unpinned registry packages through npx
The skill advertises a tightly controlled multi-agent trading-strategy lifecycle, but the finding indicates the actual behavior includes repository publishing, file copying, and git push operations that are not clearly declared in the user-facing description. In an agent setting, this kind of capability mismatch is dangerous because users may invoke what they think is a planning or analysis workflow, while the skill performs external side effects such as modifying local files or publishing to remotes, which can lead to unauthorized code release or supply-chain risk.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
一句话概述:Skill 做什么、怎么触发、输出到哪里。
<!--
选择你的设计模式,从 Skills/templates/ 目录获取对应模板:
| Pattern | 适用场景 | 模板文件 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
一句话概述:Skill 做什么、怎么触发、输出到哪里。
<!--
选择你的设计模式,从 Skills/templates/ 目录获取对应模板:
| Pattern | 适用场景 | 模板文件 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Generator)
<!--
Generator 模式:强制一致的输出结构。
用 assets/ 存输出模板,references/ 存风格指南。
指令协调检索并逐步填充。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Generator)
<!--
Generator 模式:强制一致的输出结构。
用 assets/ 存输出模板,references/ 存风格指南。
指令协调检索并逐步填充。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Inversion)
<!--
Inversion 模式:Agent 先采访用户再行动。
分阶段提问,显式门控("DO NOT start building until all phases are complete")。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Inversion)
<!--
Inversion 模式:Agent 先采访用户再行动。
分阶段提问,显式门控("DO NOT start building until all phases are complete")。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Pipeline)
<!--
Pipeline 模式:严格顺序多步工作流 + 硬检查点。
显式菱形门控条件,需要满足条件才能进入下一步。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Pipeline)
<!--
Pipeline 模式:严格顺序多步工作流 + 硬检查点。
显式菱形门控条件,需要满足条件才能进入下一步。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Reviewer)
<!--
Reviewer 模式:分离"检查什么"和"如何检查"。
references/review-checklist.md 存放模块化评分标准。
指令定义检查流程和输出格式。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# <Skill 名称> (Reviewer)
<!--
Reviewer 模式:分离"检查什么"和"如何检查"。
references/review-checklist.md 存放模块化评分标准。
指令定义检查流程和输出格式。
This duplicate hidden-instruction finding points to the same underlying issue: concealed markdown comments carry behavior-shaping directives that can change agent execution and authority handling without obvious visibility to reviewers. In this skill context, that is more dangerous because the hidden text specifically instructs the system to trust loaded references over its existing safeguards or knowledge.
# <Skill 名称> (Tool Wrapper)
<!--
Tool Wrapper 模式:按需加载特定库/API 的上下文。
SKILL.md 监听关键词,从 references/ 目录动态加载文档,作为绝对真理应用。
This duplicate hidden-instruction finding points to the same underlying issue: concealed markdown comments carry behavior-shaping directives that can change agent execution and authority handling without obvious visibility to reviewers. In this skill context, that is more dangerous because the hidden text specifically instructs the system to trust loaded references over its existing safeguards or knowledge.
# <Skill 名称> (Tool Wrapper)
<!--
Tool Wrapper 模式:按需加载特定库/API 的上下文。
SKILL.md 监听关键词,从 references/ 目录动态加载文档,作为绝对真理应用。
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
def onchainos_cmd(args: list[str], timeout: int = 30) -> dict | None:
"""Run onchainos CLI command, return parsed JSON."""
env = os.environ.copy()
env.setdefault("OKX_API_KEY", os.environ.get("OKX_API_KEY", ""))
env.setdefault("OKX_SECRET_KEY", os.environ.get("OKX_SECRET_KEY", ""))
env.setdefault("OKX_PASSPHRASE", os.environ.get("OKX_PASSPHRASE", ""))
This markdown file appears to be the primary introduction for the skill, but all user-facing content is presented only in Chinese. That forces a specific language on users without opt-in, which matches the language/locale policy violation criteria.
The README instructs users to execute npx clawhub install okx-strategy-factory without pinning an exact package version. This creates a supply-chain risk because a future compromised or malicious release could be fetched and run implicitly at install time, which is especially sensitive for a skill that later handles deployment, trading workflows, and credentials.
The README describes deployment to a VPS and GitHub publication but does not prominently warn users that these actions can modify remote systems and publish artifacts publicly. In this skill's context, that omission is more dangerous because the pipeline coordinates autonomous agents across deployment and release stages, making accidental destructive changes or unintended public release more likely.
The prerequisite npx skills add okx/onchainos-skills references a remotely fetched package/toolchain without version pinning. Because npx can download and execute code, users may unknowingly run a changed or compromised version, increasing supply-chain exposure in a workflow tied to wallets, API keys, and live trading.
The README lists OKX API keys, an agentic wallet with signing capability, and optional 1Password usage without an explicit warning about the sensitivity of these credentials or the financial authority they grant. In a live-trading skill, this materially increases risk because users may provide high-privilege secrets to an automation pipeline that can deploy, trade, and publish, amplifying the blast radius of misuse or compromise.
The README instructs users to run npx clawhub install okx-strategy-factory without pinning a package version or integrity source. That can cause users to execute whatever version is current at install time, increasing supply-chain risk if the package is compromised, typo-squatted, or updated maliciously.
The README describes an Infra agent that deploys to a VPS over SSH, manages pm2, performs health checks, and automatically rolls back, but it does not prominently warn that using the skill may modify remote systems and running services. Because this is a multi-agent automation workflow, users may underestimate that the agent can make live infrastructure changes, increasing the risk of unintended or over-broad actions.
The prerequisite npx skills add okx/onchainos-skills references a remotely resolved package/toolchain without version pinning. In a skill that later handles API keys, wallets, deployment, and publishing, unpinned bootstrap dependencies meaningfully expand supply-chain exposure.
The trigger phrases are broad enough to match common requests like strategy development, backtesting, deployment, or iteration, which increases the chance the skill activates in contexts where the user did not intend a high-impact trading or publishing workflow. Because this skill coordinates deployment and release-related actions, accidental invocation can escalate into unintended file modification, deployment, or live-trading preparation.
The description promotes deployment and live trading lifecycle support without an upfront warning that the skill may affect production systems, financial positions, wallets, VPS environments, or public releases. In the context of on-chain trading and deployment, omission of prominent warnings materially increases the risk that a user triggers actions with financial or operational consequences without appreciating the blast radius.
This shell script's descriptive comments, usage text, examples, and later user-facing messages are written in Chinese, which imposes a specific language on users. The file does not offer an opt-in language choice or explain that the tool is intentionally limited to a Chinese-speaking context.
No suspicious patterns detected.