T01 · Skill Instruction Hijacking
- Location
SKILL.md:64- Finding
Untrusted Remote Skill Instructions Are Followed Without Mandatory Isolation or Validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent web-discovery purpose, but it tells agents to fetch and follow arbitrary website-provided skill instructions with too few mandatory safety gates.
Review this skill carefully before installing. It is not showing malicious code, but it teaches the agent to trust instructions published by whatever website you are interacting with. Use it only with agents that enforce origin checks, treat fetched Markdown as untrusted, require confirmation for purchases, deployments, deletions, account changes, or credential use, and install only from a pinned, reviewed copy rather than the README curl-to-main commands.
SKILL.md:64Untrusted Remote Skill Instructions Are Followed Without Mandatory Isolation or Validation
README.md:64Installation Commands Trust Mutable and Unverified Remote Skill Content
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
Other endpoints require an API key — get one at https://bobs-store.com/developers.
### 2. Create a Skill
`/skills/search/SKILL.md` (or `/agents/search/SKILL.md`):
```markdown
---
name: search
description: >
Search and browse products in Bob's Online Store catalog.
Use when the user wants to find products by keyword, category, price, or brand.
version: 1.0.0
auth: none
base_url: https://api.bobs-store.com/v1
---
# Product Search
## Endpoint
GET /products
## Parameters
| Parameter | Type | Required | Description |
|------------|--------|----------|---------------------------------|
| q | string | yes | Search query |
| category | string | no | Filter by category |
| min_price | number | no |
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
Other endpoints require an API key — get one at https://bobs-store.com/developers.
### 2. Create a Skill
`/skills/search/SKILL.md` (or `/agents/search/SKILL.md`):
```markdown
---
name: search
description: >
Search and browse products in Bob's Online Store catalog.
Use when the user wants to find products by keyword, category, price, or brand.
version: 1.0.0
auth: none
base_url: https://api.bobs-store.com/v1
---
# Product Search
## Endpoint
GET /products
## Parameters
| Parameter | Type | Required | Description |
|------------|--------|----------|---------------------------------|
| q | string | yes | Search query |
| category | string | no | Filter by category |
| min_price | number | no |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Example
Request:
```
GET /products?q=wireless+headphones&sort=rating&max_price=100
```
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Prerequisites
- OAuth 2.0 access token (see https://devtools.cloud/docs/oauth)
- A Git repository URL (GitHub, GitLab, or Bitbucket)
## Workflow
The README instructs users to fetch remote skill content with curl and write it directly into an agent's trusted skill directory or append it to AGENTS.md, without pinning a version, verifying integrity, or warning that the downloaded instructions will influence later agent behavior. If the upstream repository is compromised or the file changes maliciously, users may silently install prompt-injection content that persists across future sessions.
The install command writes the downloaded skill into a persistent per-user skill directory, causing the instructions to influence future agent runs beyond the immediate session. Persistent prompt/instruction installation increases the blast radius of any malicious or later-compromised upstream content because it survives until manually removed or updated.
OpenClaw
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md
OpenCode
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
OpenCode
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.claude/skills/web-skills-protocol/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
OpenCode
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.claude/skills/web-skills-protocol/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
OpenCode
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.claude/skills/web-skills-protocol/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
OpenCode
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
-o ~/.claude/skills/web-skills-protocol/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
No suspicious patterns detected.