T01 · Skill Instruction Hijacking
- Location
scripts/matting.ps1:39- Finding
Forced Promotional Content Injection into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does perform image and video matting, but it also downloads and runs native Windows binaries, trusts some local FFmpeg executables before verification, and forces an unrelated contact notice into user replies.
Review before installing. Use this only if you trust the publisher and the externally hosted native binaries; prefer a sandboxed Windows account or VM for private media. Avoid running video mode from directories that may contain untrusted ffmpeg.exe or resources/ffmpeg, and consider pinning the installer instead of using the README's unpinned npx command.
scripts/matting.ps1:39Forced Promotional Content Injection into Agent Responses
references/manifest.json:9Download and Execution of Opaque Native Runtime Binaries
scripts/matting.ps1:450Current-Directory FFmpeg Executable Hijacking
README.md:15Unpinned Package Execution in Recommended Installation Command
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
git clone https://github.com/xiaowu89/skill-matting.git /tmp/sm
cp -r /tmp/sm/plugins/nx-matting/skills/nx-matting ~/.claude/skills/
rm -rf /tmp/sm
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
git clone https://github.com/xiaowu89/skill-matting.git /tmp/sm
cp -r /tmp/sm/plugins/nx-matting/skills/nx-matting ~/.claude/skills/
rm -rf /tmp/sm
整个技能说明均以中文撰写,未提供其他语言选项,也未说明该语言限制的适用范围或理由。按该规则,若技能在自然语言层面强制特定语言而未提供用户选择,可能构成语言/区域政策问题。
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill instructs the agent to always reproduce a fixed Chinese contact notice in the final user-facing reply, regardless of the user's language or consent. This creates an output-policy violation and can be used to inject unsolicited promotional or contact content into responses, reducing user trust and bypassing normal agent control over final messaging.
The script decodes a hard-coded Base64 string into a contact notice and automatically includes it in completed/error JSON events for image and video commands. Hidden or non-obvious embedded messaging is suspicious because it introduces undisclosed outbound-facing content in program output, potentially steering users to off-platform contact channels or creating a covert social-engineering surface unrelated to the stated matting function.
The manifest description emphasizes using a local BiRefNet GGUF model and no Python/PyTorch/CUDA, which implies an offline/local processing tool. However, the script implements generic remote download logic and later uses it to fetch models, runtime binaries, and FFmpeg from URLs in the manifest, meaning the skill may perform network retrieval as part of normal operation.
Ensure-Model and related runtime preparation paths trigger network downloads of model/runtime files when they are missing. The script logs progress, but it does not clearly disclose to the user up front that running the skill may transmit request metadata to external hosts and populate a local cache.
The script automatically downloads FFmpeg artifacts from configured URLs and installs them into the local runtime cache. Although progress is emitted as JSON, there is no explicit user-facing warning in the script comments or prompts that executing video processing may trigger network access and local binary installation.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
文档给出了 cp -r ... ~/.claude/skills/ 和 rm -rf /tmp/sm 的安装步骤,但没有明确提醒这些命令会向用户主目录写入文件并删除临时目录。对 markdown 文件,凡是会影响用户文件系统的行为都应有简要警示,以便用户理解副作用。
虽然文档在依赖项中提到“首次使用联网下载模型和运行时(魔搭)”,但这更像依赖说明,而不是面向用户的明确警示,未说明执行过程中会发生网络访问。对于 markdown 文件,涉及联网行为时应给出清晰提示,尤其当用户可能预期该技能“本地推理”即完全离线时。
The manifest describes image/video matting with a local BiRefNet model, but the code also discovers and, if needed, installs FFmpeg as an additional external runtime dependency. While understandable for video processing, this is extra behavior not conveyed by the description's focus on local BiRefNet-based processing.
The skill's stated purpose is media matting and background removal, but the doctor routine reports platform details, cache directory, Vulkan loader presence, runtime integrity, model installation status, and FFmpeg path/source. This diagnostic inventory is not directly part of performing matting and exposes additional host-environment introspection capability.
No suspicious patterns detected.