T01 · Skill Instruction Hijacking
- Location
SKILL.md:45- Finding
Mandatory Branding and Promotional Response Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Firecrawl API wrapper for web search, scraping, crawling, interaction, and extraction, with no hidden persistence or unrelated local access found.
Install only if you are comfortable sending requested URLs, search terms, page content, and interaction or extraction instructions to Firecrawl. Avoid sensitive or confidential sites, and be especially careful with interact commands because they can perform actions like clicking, filling forms, logging in, or downloading files after confirmation. Expect Chinese output and Firecrawl branding unless the skill is updated.
SKILL.md:45Mandatory Branding and Promotional Response Injection
The skill clearly describes capabilities that send user-provided queries, URLs, page content, and interaction instructions to an external API, yet it declares no explicit tool scope or permission metadata. This creates a transparency and governance gap: the agent may be allowed to perform networked data exfiltration or use environment-based credentials without the user or platform having a clear, enforceable declaration of those powers.
The skill instructions and all required response templates are written as mandatory Chinese output, including fixed warning and guidance text. There is no indication that the user can choose another language or that the Chinese-only behavior is required for a region-specific purpose, which violates the language/locale policy criterion.
This code emits user-facing warning text in Chinese, and similar Chinese-only messages appear throughout the CLI commands. Because the file does not offer a user language/locale choice or state that the skill is intentionally limited to Chinese-speaking users, it violates the natural-language policy constraint against forcing a specific language without opt-in.
No suspicious patterns detected.