T01 · Skill Instruction Hijacking
- Location
SKILL.md:129- Finding
Mandatory Tool Invocation Causes Non-Consensual Disclosure of Photo URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This photo-verification skill mostly does what it says, but it can send photo URLs to an external verification API too automatically and a bundled Feishu implementation logs sensitive photo and location data.
Review before installing. This skill sends photo URLs to openapi.xhey.top for verification and may return precise time and location metadata, so do not use it on private, signed, internal, or sensitive image links unless you intend that external processing. Prefer using it only after an explicit verification request, and avoid the bundled Feishu implementation until its sensitive logging and weak default authorization config are removed.
SKILL.md:129Mandatory Tool Invocation Causes Non-Consensual Disclosure of Photo URLs
feishu-trutu-verify/src/index.ts:128Sensitive Attachment, Credential Identifier, Context, and Location Data Written to Logs
feishu-trutu-verify/config.json:2Hardcoded Predictable Plaintext Authorization Credentials
babel-traverse 6.26.0 has a reported arbitrary code execution issue when processing specially crafted input during compilation/transformation. Although this appears in a dev/tooling dependency path, compromise of build or development workflows can still lead to code execution on developer or CI systems, which is a serious supply-chain exposure.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
npm install
cp .env.example .env
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
-- node /absolute/path/to/Claude_verify/mcp_server.js
### 方式二:手动编辑 `~/.claude/settings.json`
```json
{
The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.
The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.
The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.
The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.
The lockfile includes brace-expansion 2.0.2, which is flagged for multiple denial-of-service issues involving pathological brace patterns that can trigger excessive CPU or memory consumption. Even though this is a transitive dependency and likely only used during tooling or file-matching operations, keeping a known vulnerable version in the dependency graph is a real supply-chain risk.
Axios 1.13.6 is identified with multiple advisories including SSRF and prototype-pollution-related request handling risks. In this skill context, HTTP requests are core functionality, so a vulnerable HTTP client is more concerning because any weakness in proxy handling, redirects, or polluted configuration objects could affect outbound request integrity or leak credentials.
brace-expansion 1.1.12 is separately present and carries the same class of expansion-based denial-of-service issues as other vulnerable brace-expansion releases. Multiple vulnerable copies in the tree increase the chance that at least one reachable code path remains exploitable even after partial upgrades.
extract-zip 2.0.1 is flagged for arbitrary file write and symlink traversal issues during archive extraction. Even as a dev dependency, this is dangerous in developer or CI environments because processing a malicious archive can overwrite files outside the intended directory and potentially enable further compromise.
The skill sends each attachment's tmp_url to the external service in photoUrlList, which means user-supplied photo resources are disclosed to a third party for processing. This directly contradicts the metadata claim that no image content is retained or forwarded to any third party, creating a significant privacy and transparency issue, especially because signed temporary URLs may grant direct access to the underlying image bytes.
该文档整体以中文编写,且未说明该技能仅面向中文用户或中国大陆合规场景,也未提供其他语言选项。根据规则,若技能在自然语言层面隐含强制特定语言/locale 而无用户选择或明确合理说明,可构成语言/区域政策问题。
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill declares network access and use of sensitive environment credentials but does not define an explicit permission or allowed-tools scope. That increases the chance of overbroad execution and makes it harder for users or hosts to understand and constrain what the skill can access. In a skill that sends user-supplied photo URLs and handles API secrets, missing scope declarations materially weakens least-privilege controls.
The description does not clearly warn users that submitted photo URLs and resulting metadata such as capture time and GPS location will be sent to the vendor for verification. This undermines informed consent for sensitive personal and location data processing. Because photo URLs may reveal or grant access to the image itself, the omission is more dangerous than a minor documentation gap.
The invocation rule requires immediate tool use whenever a user provides a watermark-photo URL, even if the user did not request authenticity verification. That can cause unsolicited transmission of photo URLs and derived metadata to the vendor, creating privacy and consent issues and increasing the chance of unnecessary data disclosure. In a compliance-oriented skill, automatic exfiltration to a remote verifier without a clear user ask is especially problematic.
The skill requires users to enter a GroupSecret credential, but there is no user-facing warning or explanatory text about its sensitive nature or how it will be used. For code files, access to credentials should have some form of disclosure when no README or inline user warning is present.
The code logs broad execution context and verification outputs, including context, form parameters with only groupSecret masked, API responses, and final photo verification results. In this skill, those values can contain sensitive metadata such as temporary photo URLs, timestamps, locations, and operational identifiers, which contradicts the stated no-retention/no-forwarding privacy posture and increases risk of unauthorized internal disclosure through logs.
This code sends attachment temporary URLs in request bodies to https://openapi.xhey.top for verification, which is a network operation involving user data. While the code logs activity, it does not provide a user-facing disclosure, confirmation, or inline warning that photo data will be sent to an external service.
The local domain allowlist only constrains where this skill can send direct HTTP requests, but the code passes arbitrary attachment tmp_url values to the external API, which can then fetch those URLs server-side. This creates an indirect data egress path outside the apparent whitelist boundary and may expose internal or sensitive file URLs to the third-party verifier.
The code transmits photo URLs to an external verification API without any visible consent flow or warning in this file, despite the operation involving sensitive user media and potentially location/time-bearing images. In this skill context, photo authenticity verification is legitimate, but silent third-party transfer of user photos and metadata increases privacy risk and can violate user expectations or policy requirements.
The tool sends user-supplied photo URLs to an external service (openapi.xhey.top) as part of verification, but the user-facing tool behavior does not clearly disclose this data transfer at invocation time. Because photo URLs can contain sensitive information, signed links, internal hostnames, or access tokens, undisclosed transmission can cause privacy leaks or unintended sharing with a third party.
Natural-language strings in the server instructions require behavior entirely in Chinese, including a mandated tone for warnings, and the broader tool text is also Chinese-only. The file does not offer language selection or state that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.
No suspicious patterns detected.