T01 · Skill Instruction Hijacking
- Location
SKILL.md:938- Finding
Generated Skills Attempt to Override the Agent Instruction Hierarchy
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent goal, but it needs Review because it can collect and store private workplace communications, credentials, browser-session data, and persistent persona instructions with weak safeguards.
Install only if you have explicit authorization from your organization and the people whose communications may be processed. Avoid private-chat collection, browser scraping, raw screenshots, and voice/identity cloning use cases unless there is documented consent. Use narrowly scoped read-only credentials, do not use the example.com OAuth redirect, pin external tools before use, and review every generated skill before enabling it.
SKILL.md:938Generated Skills Attempt to Override the Agent Instruction Hierarchy
tools/feishu_mcp_client.py:94Runtime Execution of an Unpinned npm Package with Feishu Credentials
tools/feishu_mcp_client.py:45Plaintext Credential Files Are Written Without Enforced Restrictive Permissions
SKILL.md:637OAuth Authorization Code Is Redirected to an Unrelated Plaintext HTTP Endpoint
SKILL.md:679Feishu User Access Token Is Passed Through Command-Line Arguments
The roadmap proposes cloning a person's voice from meeting recordings and voice messages without any mention of informed consent, biometric data handling, impersonation safeguards, or abuse prevention. Voiceprints are sensitive biometric identifiers, and in this skill's context the feature would enable highly convincing impersonation of real individuals, increasing risks of fraud, social engineering, harassment, and severe privacy violations.
The description presents a broader end-to-end skill: collect Feishu/DingTalk data, generate a colleague-derived AI Skill including Work + Persona, and support continuous evolution. The supplied code only covers one subset of that pipeline: DingTalk data collection. It does not generate any AI Skill, persona, or evolution behavior. It also does not include Feishu support in this chunk. Additionally, the declared permissions are empty, but the code clearly accesses sensitive enterprise resources (contacts, docs, tables, and chat records via browser automation) and writes them to disk. That is a material mismatch between the declared description/permissions and the actual behavior.
The declared description centers on building an AI representation of a colleague through automatic Feishu/DingTalk data collection and persona/skill generation. The supplied code does none of that directly. It only processes email data from local files (.eml, .mbox, .txt), filters by sender, extracts text, performs simple categorization, and outputs formatted content for potential downstream use. While this could be a supporting component in a broader colleague-distillation pipeline, the actual code chunk's primary purpose and accessed resource type (email files) differ materially from the declared Feishu/DingTalk auto-collection and persona-generation functionality.
The description presents a broader end-to-end skill that both collects enterprise data from Feishu and DingTalk and transforms it into a colleague-derived AI Skill with persona/work synthesis and ongoing evolution. The supplied code only implements a Feishu data collector. It performs user lookup, group/private message retrieval, document/wiki search and content fetching, optional bitable reading, token exchange/setup, and local file export. There is no DingTalk code, no generation of persona/work skill artifacts, and no continuous evolution mechanism. Additionally, the declared permissions are empty, while the code clearly requires and uses substantial access to messaging, contacts, docs, wiki, drive, and bitable resources. This is a material description-behavior mismatch.
The declared description promises an end-to-end colleague-distillation capability: collecting Feishu/DingTalk data, producing a Work Skill and Persona, and continuously evolving that representation. The supplied code only implements one narrow component: browser-based extraction of Feishu content using an existing Chrome login state. That means its actual behavior is materially different from the declared purpose in two ways. First, it includes a sensitive undeclared capability: accessing authenticated Feishu resources and message history by reusing the user's browser profile. Second, it does not implement the core claimed functionality of generating a colleague persona/skill or any continuous evolution pipeline. It also does not support DingTalk despite that being explicitly declared. Therefore the description does not accurately represent what this code chunk actually does.
The code chunk is narrowly focused on retrieving Feishu content through an MCP server: it configures Feishu credentials, calls MCP tools to read docs/wiki/messages, filters chat messages, lists wiki documents, and saves output. It does not implement any logic for 'distilling a colleague,' generating an AI Skill, producing a Work/Persona model, or supporting continuous evolution. It also does not include any DingTalk integration. While Feishu data collection is loosely aligned with part of the description, the primary declared purpose is a higher-level colleague-to-skill generation system, which this code does not perform. Additionally, the declared permissions are empty, but the code clearly accesses enterprise documents and messages using app/user tokens.
The declared description presents a broader end-to-end skill for automatically collecting workplace chat data from Feishu/DingTalk and transforming it into an evolving AI representation of a colleague. The supplied code only implements a narrow preprocessing utility: it reads an input file, extracts messages for a named sender, classifies them into long/decision/daily buckets, and writes formatted output. This is related to the overall theme but materially narrower and missing the key advertised capabilities. No undeclared sensitive behavior is evident, but the description significantly overstates what this code chunk actually does.
The description promises an end-to-end system that automatically collects colleague data from Feishu/DingTalk and distills it into an evolving AI Skill with Work and Persona generation. The supplied code does not access Feishu, DingTalk, network resources, messages, or external APIs at all. Instead, it is a filesystem utility that takes already-prepared meta/work/persona content and writes or updates local skill files, including SKILL.md, meta.json, and version backups. While versioning and corrections loosely relate to 'continuous evolution,' the core claimed capabilities—automatic collection and generation—are absent. Therefore the code's actual primary purpose materially differs from the declared description.
The description says the skill auto-collects Feishu/DingTalk data and generates a Work Skill + Persona for continuous evolution. The supplied code chunk does something materially different: it is specifically a Slack data collector using Slack APIs and bot scopes, with no Feishu or DingTalk integration at all. Its primary implemented function is message collection from shared Slack channels and outputting text/JSON files for downstream analysis. While downstream analysis is hinted at in comments, this code itself does not generate the promised Work Skill or Persona. Because the accessed resource (Slack) differs from the declared platforms (Feishu/DingTalk), and the implemented capability is narrower and materially different from the declared purpose, this is a clear mismatch.
The declared description promises a system for ingesting colleague data from Feishu/DingTalk and generating/evolving AI Skill representations. The supplied code does not perform data collection, API access, content generation, or evolution logic. Instead, it manages local filesystem versions of existing skill files (SKILL.md, work.md, persona.md) via list/backup/rollback/cleanup operations. This is a materially different primary purpose and introduces an undeclared capability: version archive management and rollback. Therefore the description does not accurately represent the code chunk.
The description markets the skill as a colleague-distillation helper but does not clearly disclose that it may collect private messages, documents, spreadsheets, emails, and profile data into a persistent knowledge base. That omission undermines informed consent for highly sensitive processing.
The workflow normalizes aggregating messages, documents, spreadsheets, emails, and pasted text into a persistent knowledge base for later synthesis into a persona and skill. Centralizing this breadth of sensitive data creates a durable surveillance dataset that can expose personal, confidential, and proprietary information if misused or leaked.
This section directs collection of full private Feishu conversations but does not present a conspicuous warning or consent gate immediately beforehand. Collecting complete two-party message history for persona synthesis is highly intrusive and requires explicit notice and authorization.
The instructions direct ingestion of full private chat histories and contact-visible identity data to build a persona profile of another person. This is a classic over-collection pattern: it gathers sensitive communications and personal identifiers far beyond what is necessary for many legitimate use cases, with significant privacy, insider-risk, and misuse potential.
The skill instructs the agent to send a real message to a target user solely to discover private chat metadata, causing an externally visible action against a third party without that person's consent. This can expose the operator, leak that monitoring is occurring, and facilitate unauthorized collection of private communications.
The workflow explicitly endorses browser-based scraping of DingTalk message history when the platform API does not support such access. Bypassing platform limits through scraping can violate access controls, terms of service, and privacy expectations while collecting highly sensitive employee communications.
Referenced artifact was not completely inspected
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)
Referenced artifact was not completely inspected
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)
Referenced artifact was not completely inspected
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)
Referenced artifact was not completely inspected
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)
Using rm -rf colleagues/{slug} with a user-influenced parameter creates a path-manipulation and destructive deletion risk. If slug is malformed or insufficiently validated, an attacker could cause deletion outside the intended directory or remove unexpected content.
/delete-colleague {slug}:
确认后执行:
rm -rf colleagues/{slug}
The skill is explicitly empowered to write and edit skill files, including updating stored behavior and persona content over time. Self-modifying or self-extending behavior increases persistence and can entrench unsafe instructions or poisoned data without robust review gates.
| Feishu docs (MCP App Token) | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/feishu_mcp_client.py` |
| DingTalk auto-collect | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/dingtalk_auto_collector.py` |
| Parse email .eml/.mbox | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/email_parser.py` |
| Write/update Skill files | `Write` / `Edit` tool |
| Version management | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/version_manager.py` |
| List existing Skills | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/skill_writer.py --action list` |
This is the English duplicate of the instruction to send a message to the target user in order to obtain private chat metadata. It creates the same risk of unauthorized contact, privacy intrusion, and covert collection of private conversation context.
This English section explicitly approves browser scraping of DingTalk message history despite lack of official API support. That instruction normalizes circumvention of platform boundaries to harvest sensitive communications and materially raises privacy and compliance risk.
Prompting users to upload chat screenshots as a fallback increases the chance of exposing unrelated conversation context, third-party personal data, and confidential information that cannot be easily filtered. Images are especially hard to sanitize consistently before ingestion and storage.
- `knowledge/{slug}/bitables.txt`
- `knowledge/{slug}/messages.txt`
If message collection fails, prompt user to upload chat screenshots.
---
No suspicious patterns detected.