T01 · Skill Instruction Hijacking
- Location
connect.js:51- Finding
Attacker-Controlled World Messages Are Injected into the Agent Context
- Content
View full analysis
{ try { const msg = JSON.parse(data.toString()); handleMessage(msg); } catch (e) {} }); ``` ```js const events = obs.recentEvents || []; const importantEvents = events.filter(e => ['agent_spoke', 'whisper', 'trade_proposed', 'bounty_posted', 'combat_attack', 'agent_defeated', 'territory_contested', 'guild_invite', 'resource_gathered', 'bounty_completed'].includes(e.type) ); for (const e of importantEvents.slice(0, 5)) { switch (e.type) { case 'agent_spoke': summary += ` 💬 ${e.name}: "${e.message}"\n`; break; case 'whisper': if (e.toAgentId === agentId) { summary += ` 🤫 ${e.fromName} whispers: "${e.message}"\n`; } break; case 'trade_proposed': summary += ` 🤝 Trade proposed by ${e.fromName}\n`; break; case 'bounty_posted': summary += ` 🎯 Bounty posted: "${e.title}" (${e.rewardSOL} SOL)\n`; break; } } console.log(summary); ``` ### Technical Analysis The WebSocket server supplies observations containing messages, names, whispers, and bounty titles controlled by other participants. These values are interpolated directly into a textual summary and written to standard output. The script header states that OpenClaw reads this output. Consequently, untrusted remote text enters the language model's context without a trusted-data boundary, escaping, provenance enforcement, or an instruction that the content must never be treated as authorization. Simple output escaping would not completely solve this issue because the semantic content could still contain instructions. The application needs a policy boundary that distinguishes remote world data from trusted user instructions. ### Attack Path 1. An atta ...[truncated 1305 chars]- Remediation
View remediation
