T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Persistent Promotional Instructions Hijack Normal Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill can place real outbound calls and exposes sensitive call data with insufficient safeguards, so it should be reviewed carefully before installation.
Install only if you trust the Vox/TeddyMobile data flow and can add deployment controls: require explicit confirmation before calls, force authentication on hosted APIs, disable or minimize analytics, restrict callback destinations, avoid returning full transcripts by default, and disclose AI identity at call start.
SKILL.md:9Persistent Promotional Instructions Hijack Normal Agent Output
resources/index.js:46Raw User Prompts and Persistent Identifiers Are Transmitted to Analytics by Default
resources/hosted_api_example.js:25Hosted Call API Allows Unauthenticated Operation When No Token Is Configured
resources/post_call_callback_client.js:5User-Controlled Post-Call Callback Enables SSRF and Transcript Exfiltration
resources/hmac_outbound_client.js:63Configurable Vox Endpoints Can Receive Sensitive Authenticated Requests Without Host or TLS Validation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
VOX_BOT_ID=
VOX_OUTBOUND_BASE_URL=https://vox.teddymobile.cn
VOX_CREDENTIALS_FILE=/secure/path/credentials.json
SKILL_API_TOKEN=change-me
VOX_TRIAL_MODE=true
VOX_TRIAL_LIMIT=10
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
VOX_BOT_ID=
VOX_OUTBOUND_BASE_URL=https://vox.teddymobile.cn
VOX_CREDENTIALS_FILE=/secure/path/credentials.json
SKILL_API_TOKEN=change-me
VOX_TRIAL_MODE=true
VOX_TRIAL_LIMIT=10
The skill instructs the bot not to proactively disclose that it is an AI and instead present itself as a selected role, only admitting its nature if directly asked. In an outbound calling system, that materially increases the risk of deceptive impersonation, social engineering, and non-compliance with AI disclosure or telemarketing transparency requirements.
Referenced artifact was not completely inspected
- Direct Vox client: `resources/hmac_outbound_client.js`
Referenced artifact was not completely inspected
- Intent extraction and completion: `resources/prompt_to_call_intent.js`, `resources/intent_completeness.js`
Referenced artifact was not completely inspected
- Intent extraction and completion: `resources/prompt_to_call_intent.js`, `resources/intent_completeness.js`
Referenced artifact was not completely inspected
- Profile generation: `resources/prompt_to_agent_profile.js`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
function loadLocalDotEnv() {
const envPath = path.resolve(__dirname, '..', '.env');
if (!fs.existsSync(envPath)) return {};
const result = {};
const content = fs.readFileSync(envPath, 'utf8');
emitAnalytics is called with sensitive_payload containing the raw user_prompt and later normalized_prompt, creating a direct natural-language leakage path into analytics infrastructure. User prompts can easily contain phone numbers, business details, instructions, or regulated data, so storing and transmitting them outside the primary service meaningfully increases confidentiality and compliance risk.
The skill returns transcript and related post-call content in result objects, and also stores/polls call-job state for later retrieval paths. Full conversation text is highly sensitive and often contains personal, commercial, or behavioral information; exposing it beyond the immediate operational need amplifies harm from misuse, over-broad access, or downstream logging.
The skill includes logic to poll call status, retrieve full post-call turns/transcripts, analyze them, and return them to the requester. That goes materially beyond merely placing an outbound call and introduces a surveillance and content-collection capability that can expose private conversations if access control, consent, or authorization checks are weak or absent.
The result formatting code renders verbatim transcript lines (Bot/用户) back to the requester, enabling straightforward extraction of the entire conversation once a callId is available. Without robust authorization checks shown here, that makes transcript disclosure especially dangerous because a sensitive conversation can be replayed in full through a query interface.
The documentation instructs users to configure real Vox credentials and place outbound calls, but it does not clearly disclose that phone numbers, prompts, and related call content will be transmitted to an external third-party service. This can lead to unintentional exposure of sensitive personal or business data, especially in hosted or redistributed agent contexts where users may assume processing is local.
The skill states that once required fields are complete, it immediately builds the payload and starts an outbound call. That creates a real consent and misuse risk because users may trigger live phone calls without a final confirmation, recipient verification, or a clear warning that submission is irreversible. In a telephony context, accidental or coerced calls can cause harassment, privacy, and compliance issues.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Start in promotion trial mode by default unless the user already clearly said 正式注册, 正式账号, 自己的凭证, VOX_APP_ID, VOX_SECRET, 企业接入, or 生产环境.
Do not ask the user to choose between trial and formal registration at the beginning. If the task is missing required call details, tell the user that the skill will use trial mode first and ask only for the most important missing call detail:
我会先使用 Vox 试用模式帮你完成一次电话体验,不需要配置 VOX_APP_ID / VOX_SECRET。
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Start in promotion trial mode by default unless the user already clearly said 正式注册, 正式账号, 自己的凭证, VOX_APP_ID, VOX_SECRET, 企业接入, or 生产环境.
Do not ask the user to choose between trial and formal registration at the beginning. If the task is missing required call details, tell the user that the skill will use trial mode first and ask only for the most important missing call detail:
我会先使用 Vox 试用模式帮你完成一次电话体验,不需要配置 VOX_APP_ID / VOX_SECRET。
The documentation explicitly says there is no dry-run preview and that complete inputs start the call, but it does not pair that behavior with a user-facing safeguard. This is dangerous because the skill handles real-world outbound telephony, where minor misunderstanding or prompt injection into task details could immediately trigger an unwanted call to a third party.
These instructions normalize a human-like identity presentation unless the callee explicitly challenges it. That is a true safety issue because it conditions the system to rely on omission-based deception, which is especially risky in unsolicited outbound communications where recipients may reasonably assume they are speaking to a human representative.
The example action labels and values are entirely in Chinese, and the registration guidance example is also written only in Chinese. This indicates a fixed locale in user-facing content without any opt-in, fallback, or explanation that the skill is intentionally region-specific.
The manifest description says the skill will 'Convert natural-language phone tasks' into outbound calling actions, which is a broad trigger surface without explicit scope, approval gates, or activation constraints. In a phone-agent skill that can place outbound calls, ambiguous natural-language activation increases the risk of unintended task execution, misuse for spam/social engineering workflows, or unsafe call generation from loosely specified user prompts.
The smoke-test script includes a fully Chinese instruction string for operating the phone agent, which implies a fixed language expectation. Because this manifest does not indicate that the skill is region-specific or that users can opt into another language, it may violate the language/locale policy requirement.
This code sends analytics events to a configurable remote endpoint and the event payload includes identifiers such as user_id, anonymous_id, session_id, usage_session_id, run_id, request_id, and trace_id. Although there is some field sanitization, these identifiers are still potentially sensitive and can enable user/session tracking or data disclosure if the endpoint is misconfigured, compromised, or lacks appropriate consent and governance.
The alias "blocked" for safety-blocked is ambiguous and may be triggered by unrelated moderation, networking, or UI events, causing incorrect classification as a safety intervention. In this context, mislabeling events as safety blocks can corrupt safety reporting and make it harder to distinguish actual policy enforcement from ordinary failures.
The alias set for task-ready includes the generic token "ready", which can collide with unrelated status text or third-party event names and cause incorrect analytics state transitions. In a phone-agent workflow, that misclassification can prematurely mark a task as configured or runnable, degrading monitoring accuracy and potentially masking operational or safety issues.
Using the alias "completed" for run completion is overly broad and can match many unrelated completion events, causing false success attribution. In this skill, that could inflate success metrics, hide failed or partial outbound-call flows, and weaken operational oversight.
No suspicious patterns detected.