T01 · Skill Instruction Hijacking
- Location
references/output-rules.md:3- Finding
Mandatory promotional instructions hijack the agent's final response
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent China social-media research purpose, but it gives the agent broad automatic behavior and opens generated HTML reports that are built unsafely from untrusted data.
Review before installing. Use it only for intentional China social-media research, avoid sensitive internal names or confidential topics unless you are comfortable sending them to redfox.hk, and do not let it automatically open generated HTML reports until the HTML escaping and link validation issues are fixed.
references/output-rules.md:3Mandatory promotional instructions hijack the agent's final response
scripts/cn_last30days.py:614Generated HTML permits active-content injection through unescaped keywords and URL attributes
Enabling implicit invocation without tight trigger constraints makes the skill available for automatic selection even when user intent is ambiguous. Because this skill is designed to analyze social-media discussions across multiple Chinese platforms, accidental invocation can lead to overbroad data gathering, incorrect assumptions about locale/platform relevance, and misrouting of user requests.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
</div>'
)
xhs_notice = (
'<div style="background:#fff3cd;border:1px solid #ffc107;border-radius:8px;padding:10px 14px;margin-bottom:14px;color:#664d03;font-size:13px;line-height:1.6">'
'⚠️ 受小红书风控规则限制,部分作品链接可能无法正常跳转,您可复制对应作品标题前往小红书搜索查看,感谢理解🙇♀️🙇♀️'
'</div>'
) if pkey == "xhs" else ""
no_data_html = "<div class='no-data-hint'><p>未查询到相关内容,建议更换关键词重试。</p></div>" if not items else ""
panels_html += (
'\n <div class="tab-panel" id="panel-' + pkey + '" style="display: ' + display + '">\n'
' ' + error_html + '\n'
' ' + xhs_notice + '\n'
' <div class="card-list">\n'
' ' + cards + '\n'
' </div>\n'
The README says the skill automatically runs WebSearch before calling the engine and automatically merges and interprets results. Autonomous external actions increase the chance of unreviewed query expansion, unintended data sharing, and opaque decision-making that users may not realize is happening before information is sent out.
### Highlights
- **Pre-research mechanism**: Automatically runs WebSearch to extract trending terms before calling the engine, optimizing query strategy.
- **Smart merging**: Automatically merges related keywords into a single call to reduce API invocations.
- **Signal interpretation**: Automatic interpretation of key metrics like Xiaohongshu save/like ratio, Douyin share count, and WeChat read count.
The README explicitly states the skill ships with a built-in free public API key while also warning not to hard-code or expose keys. A bundled shared credential creates clear risk of secret exposure, abuse by third parties, quota exhaustion, and use of a common identity across users, which can also enable traffic attribution or service disruption.
The invocation guidance is extremely broad, telling users they can simply describe topics in natural language with no fixed commands. In an agent environment, loose trigger boundaries can cause over-invocation, unintended external searches, and accidental transmission of sensitive or irrelevant user content to third-party services.
The README says users can 'directly use natural language' without fixed commands and provides example phrases like '帮我研究一下…' and '对比一下…', which overlap with common everyday requests. It does not define clear activation boundaries, exclusions, or negative examples, increasing the risk of unintended invocation.
The skill instructs the agent to automatically open a generated HTML file after analysis, which is not necessary to fulfill the tool's research purpose. Auto-opening local HTML can trigger browser execution of embedded active content or unexpected external requests, and it removes user control over a side effect that goes beyond generating a report.
The skill directs automatic HTML generation and opening without warning or confirmation, creating an unnecessary action chain after the main task completes. In an agent context, removing confirmation for browser-launching behavior increases the risk of surprising file execution, privacy leaks through external resource loading, and reduced operator oversight.
The display name, description, and default prompt are entirely in Chinese and direct analysis of Chinese social media content, but the manifest does not offer a language or locale opt-in choice. This can violate language/locale policy when a skill implicitly assumes a specific language without explicit user selection or documented regional justification.
The default prompt is broad enough that the skill could be selected for generic research or trend-analysis requests without a clear user request for this specific China social-media workflow. In combination with implicit invocation, this increases the chance of unintended routing, causing the agent to apply platform-specific assumptions or collect/analyze content the user did not explicitly ask for.
The template mandates a Chinese-language badge and, throughout the document, requires output in Chinese formatting and headings. This is a natural-language policy concern because it enforces a specific language/locale rather than offering a user-selectable option or documenting a justified regional-only scope.
The manifest describes a social-media topic research tool for searching and comparing discussion trends across platforms. While network access is expected, automatically reading secrets from process environment variables and ~/.qoder/apis/redfox.json goes beyond the user-facing research purpose and introduces credential-access behavior not disclosed in the manifest description.
The skill sends user-supplied keywords and source metadata to a third-party service without any user-facing privacy notice or consent mechanism. If users input sensitive business topics, incident terms, client names, or internal project identifiers, those terms are disclosed externally and may be logged by the remote provider.
The manifest emphasizes searching recent discussions and cross-platform analysis, but the implementation persistently writes output files under ~/Downloads/CnLast30Days unless configured otherwise. Local file creation is not merely incidental logging here; it is a default side effect that materially expands behavior beyond the described search/analysis function.
The file brands the skill as 'China Social Media Topic Research' and immediately frames outputs around Chinese platforms and a China-focused research context. While the domain is region-specific, the README does not explicitly state that this locale specialization is intentional or that users are opting into a China-only analysis scope.
The manifest frames the skill as an on-demand social media research and cross-platform analysis tool. L94 adds a persistent 'subscribe once and receive automatic updates' capability, which implies scheduled monitoring or push delivery beyond the described research use case and is not otherwise declared in the manifest context provided.
All user-facing instructions and examples are in Chinese, and the document does not state that Chinese is optional or required for a justified region-specific reason. This can constitute a language/locale policy issue because it effectively forces a specific language without user opt-in.
The documentation minimizes side effects by saying the JSON-to-HTML step does not write Markdown, while the command still writes an HTML artifact to disk and then opens it. This is a real transparency and safety issue because it can mislead the operator about filesystem changes and downstream execution in a browser.
The output document is hardcoded with lang="zh-CN", and the tool's strings are entirely fixed to Chinese. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.
No suspicious patterns detected.