T01 · Skill Instruction Hijacking
- Location
references/due_diligence_report.md:19- Finding
Mandatory Promotional Content Injected into Agent Reports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its company-search purpose, but it needs user review because it sends business/person lookup data and API credentials to Riskbird, including private API keys in URL parameters.
Install only if you are comfortable sending company names, person names, entids, and due-diligence queries to Riskbird. Prefer the built-in shared key for low-sensitivity testing; if you configure a private FN_API_KEY, understand that this skill sends it in URL parameters and avoid printing it in shared terminals or logs. Review generated due-diligence reports before relying on or redistributing personal or corporate risk data.
references/due_diligence_report.md:19Mandatory Promotional Content Injected into Agent Reports
scripts/client.mjs:162Private API Keys Transmitted in URL Query Parameters
scripts/env.mjs:1Shared API Credential Hardcoded in the Distributed Package
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
macOS / Linux
printenv FN_API_KEY
Windows PowerShell
The setup guide explicitly instructs users to print the API key to the terminal in order to verify configuration, but does not warn that this reveals the credential on screen and may persist in terminal scrollback, screen recordings, shared sessions, or operational logs. While this is framed as troubleshooting guidance rather than credential theft, it increases the chance of accidental secret exposure.
The skill is configured with auto_invoke and very broad enterprise-query keywords/examples, which increases the chance it activates on loosely related prompts without a clear user request. In this context, unintended activation can send company or person names to an external due-diligence service, creating avoidable privacy leakage and surprising external lookups.
The skill documentation says it is 'out of the box' and uses a built-in shared API key, but it does not clearly warn users that their company/person queries are transmitted to an external third-party service. Because the built-in key is shared, users may also not realize their requests are being made under a communal credential, which raises privacy, auditability, and consent concerns.
The guidance instructs the agent to compile and present a detailed due diligence report including company identifiers, legal representative, shareholders, senior staff, enforcement history, and other risk data, but provides no guardrails on privacy, data minimization, accuracy caveats, or appropriate downstream use. In a due-diligence context this can facilitate profiling and redistribution of sensitive corporate and personal information, especially when the report is presented as authoritative without limitations or warnings.
Line L095 states that English search is invalid and users 'must pass Chinese', which imposes a language constraint in natural-language documentation. The file does not offer a user opt-in, alternative language handling, or a documented regional/compliance justification for this restriction.
The code appends the API key to the request URL and sends request parameters to a remote API via fetch, but there is no confirmation prompt, logging, print statement, or explanatory comment disclosing this network transmission to the user. Because these requests may include user-provided data and credentials, they fall under safety-relevant network operations lacking visible warning in this file.
The file hardcodes a shared API credential and automatically falls back to it whenever a user key is not provided. Publishing embedded credentials in a distributable skill allows anyone with access to the package to extract and reuse the key, which can lead to unauthorized API consumption, quota exhaustion, billing abuse, and loss of control over the upstream account.
The skill silently uses an embedded API key without informing the user, which hides the fact that requests are being authenticated under a publisher-controlled shared credential. This reduces transparency, prevents informed consent about service usage and limits, and increases the risk of unnoticed abuse or service disruption when the shared key is revoked or exhausted.
The aliases in this range include broad, everyday business terms such as supplier-, contract-, boss-, and interview-related phrases that are not uniquely indicative of an intent to run a company-risk search skill. This can cause unintended invocation, leaking user intent into an external enterprise lookup workflow or triggering data retrieval the user did not explicitly request. In a due-diligence skill that may access sensitive corporate risk data, ambiguous triggers make accidental activation more concerning than in a low-impact utility skill.
The tool set defines very broad trigger keywords such as generic enterprise/company search terms that can match many ordinary user requests and cause unintended invocation of sensitive company-intelligence lookups. Because these tools return business identity, shareholder, executive, litigation, and penalty data, over-broad routing increases the chance of unnecessary data access and privacy-impacting enrichment beyond the user's explicit intent.
The description states "英文搜索无效,必须传中文名称" and the parameter description repeats that the query "必须是中文". This is a natural-language locale restriction with no user choice or opt-in, which can violate language/locale policy expectations.
SQP-3 applies to all file types and covers language policy violations when a skill forces a specific language without user opt-in. This document presents all operational instructions exclusively in Chinese, with no indication of optional locale support or a documented region-specific justification in the file.
The description states this is a China enterprise-query skill and line 129 requires enterprise names to always be output using the full registered Chinese company name, but there is no mention of offering users a language or locale choice. This imposes a locale-specific output convention even though the examples include English-language prompts.
The instructions and required output template mandate Chinese-language report generation, but the file does not state that the skill is China-specific or provide any user opt-in for language/locale. Under the policy, forcing a specific language without choice or clear justification is a natural-language policy concern.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and field definitions only in Chinese, with no user opt-in, alternative language, or justification that the skill is limited to a Chinese-language or China-specific audience.
The file title and all field descriptions are written in Chinese, but the document does not state that the skill is China-specific or that language selection is optional. Under the language/locale policy rule, a fixed language can be a policy issue when no opt-in or justification is provided.
The thrown error strings are written only in Chinese, which imposes a specific language on user-visible output without any language selection or opt-in mechanism. This is a natural-language policy concern because the skill does not indicate that it is region- or language-specific, nor does it offer alternatives.
The user-facing help text and examples are entirely oriented around Chinese-language queries and Chinese company lookup, including example input like "企业股东信息". This can be read as a locale/language constraint, but the file does not explicitly state that the tool is region-specific or that other languages may also be used.
The natural-language configuration hard-codes activation terms in specific languages/locales, including many Chinese-only triggers and some English transliterations. Because the file provides no indication that users can choose language behavior or that the locale restriction is intentional and documented, it may violate language/locale policy expectations.
No suspicious patterns detected.