T01 · Skill Instruction Hijacking
- Location
references/workflow.md:3- Finding
Skill instructions attempt to override host-level agent behavior
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real procurement-system integration, but it asks for raw passwords, stores usable access tokens locally, persists remote tool metadata, and can change financial/business records.
Review before installing in any production SRM environment. Use a limited test account first, verify the Yidea API host, avoid pasting real passwords into chat or command lines, protect or remove config/config.json after use, and require explicit review of every create, update, delete, order, contract, receiving, deduction, or payment action.
references/workflow.md:3Skill instructions attempt to override host-level agent behavior
references/auth.md:18Unvalidated remote tool definitions are written to persistent agent memory
references/yidea-provision.js:30Bearer token is persisted in a plaintext tracked configuration path
references/yidea-provision.js:91Plaintext password is accepted through process command-line arguments
references/yidea-provision.js:9Configuration-controlled endpoint can receive raw user credentials without origin validation
references/yidea-provision.js:91Documented authentication module cannot be safely imported
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.nuxt
# dotenv environment variable files
.env
.env.local
.env.*.local
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.nuxt
# dotenv environment variable files
.env
.env.local
.env.*.local
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# dotenv environment variable files
.env
.env.local
.env.*.local
# npm cache directory
The declared description frames the skill as business/form processing, but the behavior includes credentialed remote authentication, local token/config storage, MCP connectivity testing, and tool enumeration. This mismatch hides security-relevant capabilities from reviewers and users, making risky behavior easier to invoke without informed consent.
The trigger keywords are extremely broad business terms like '采购', '合同', '申请', and '管理', which can match ordinary conversation and unintentionally activate a write-capable procurement skill. Because the skill can drive sensitive actions such as vendor, contract, pricing, and payment operations, accidental invocation materially raises the chance of unintended data access or modification.
The skill instructs the agent to collect the user's raw username and password in chat on every use, which creates a direct credential-harvesting path and unnecessary exposure of secrets to the agent, logs, and any downstream integrations. Requiring this for routine SRM actions is especially dangerous because the same credentials likely unlock sensitive supplier, contract, and payment workflows.
The skill tells the agent to request a username and password directly but provides no safe-handling warning, no minimization guidance, and no secure collection mechanism. This normalizes unsafe secret sharing in chat and increases the likelihood of credential leakage via transcripts, telemetry, or reuse across systems.
Mandating that the agent solicit and accept system credentials in plain conversation is a direct secret-handling anti-pattern. In this skill, the danger is amplified by the surrounding procurement and payment capabilities, because compromised credentials could enable unauthorized access to supplier data, contracts, orders, and financial workflows.
The README describes very broad natural-language invocation patterns such as '帮我发起采购申请' and '查询一下待办' without clear scoping or confirmation boundaries. In an agent environment, this raises the chance of accidental activation from ordinary conversation, which is especially risky because the skill can perform business actions like procurement, contract, and payment workflows.
The install command uses npx clawhub@latest, which fetches and executes the latest published package at runtime instead of a pinned, reviewed version. That creates a supply-chain risk: if the package or one of its dependencies is compromised, users installing the skill could execute attacker-controlled code on their machine.
The README states that after login the system saves config/config.json to the workspace and stores values including tenantId, token, and baseUrl, but it does not clearly warn users that authentication data will be written locally. This can expose reusable credentials or session tokens to other local users, backups, logs, or accidental source control commits.
The functionality list advertises create, update, delete, ordering, contract, receipt, and payment capabilities without prominent warnings about their destructive or financially binding nature. In this procurement context, accidental or socially engineered use could create unauthorized orders, alter supplier data, delete records, or trigger payment-related actions with real business impact.
The skill exposes network and environment-backed operational capability but does not declare any explicit tool scope or allowed-tools boundary. That makes the effective authority of the skill less transparent and increases the risk of overbroad execution or misuse when handling procurement operations and credentials.
The description and trigger design are written to operate in Chinese and the skill appears to assume Chinese-language usage, but it does not explicitly offer a language option or state that the skill is intentionally limited to Chinese-speaking users for a documented reason. This can constitute a language/locale policy issue under the natural-language policy rules.
Conversational examples such as '帮我买', '替我买', or '看看我有什么待办' are broad enough to be triggered during casual discussion, increasing the risk that the skill activates without the user realizing it. In a procurement context, even read-only activation can expose sensitive business data, and write-capable flows amplify the risk.
The skill supports create, update, and delete operations for procurement records without requiring clear risk disclosures or explicit confirmation for potentially irreversible business changes. In SRM/procurement systems, accidental or rushed mutations can impact supplier onboarding, pricing, orders, receiving, and payments.
The documentation directs the agent to run local Node/PowerShell-style commands as part of normal operation, expanding the skill from business logic into local command execution. Even if intended for integration, this increases attack surface by enabling filesystem interaction, script execution, and potential command misuse beyond the procurement use case.
The entire skill is written to operate only in Chinese and does not offer the user any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the regional constraint is explicitly documented and justified.
The examples "帮我买" and "替我买" are overly broad natural-language triggers that can match casual conversation and cause the agent to enter a procurement workflow unexpectedly. In a skill that can initiate business actions and collect or submit form data, ambiguous activation increases the risk of unintended purchases, workflow launches, or disclosure of procurement-related schemas and records.
The skill explicitly instructs storing server-returned tool definitions into session context and persistent memory without any minimization, TTL, or user notice. Persisting authentication-derived capability metadata can unnecessarily broaden later tool access, leak internal schemas across turns, and create downstream abuse if memory is exposed or reused in unrelated conversations.
The login response is authentication-derived, and the guidance says to persist returned tool definitions into memory for future use. Even if the tools array does not contain the token itself, retaining auth-scoped capability data beyond immediate need can enable privilege confusion, unintended reuse across tasks, and additional exposure if session memory is inspected, serialized, or shared.
The file’s instructions and examples require responses to be presented in Chinese, including fixed Chinese phrasing for successful operations shown to customers. This is a natural-language locale policy constraint, but the document does not mention any user preference, opt-in, or justified region-specific limitation.
The entire protocol is written as mandatory operational guidance in Chinese and does not offer any language choice or state that the skill is region-specific. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The protocol requires the agent to automatically query related records as soon as it detects a query_ field, without any user confirmation or visibility into what data source will be accessed. In an SRM/procurement context, those related tables may contain supplier, pricing, contract, or workflow data, so automatic lookup can disclose metadata or records the user did not explicitly request and may bypass expected consent or least-privilege interaction patterns.
The instruction hard-codes a Chinese user-facing fallback message: 未找到匹配的关联记录,请检查数据或联系管理员. This enforces a specific language for end-user communication without indicating that the skill is region-specific or that users can choose their preferred language.
No suspicious patterns detected.