T01 · Skill Instruction Hijacking
- Location
SKILL.md:66- Finding
Automatic Trust of Project-Controlled Context Enables Skill Instruction Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 66 and 101
Vulnerability Type: Untrusted local context promoted to agent instructions
Risk Level: MediumComplete Vulnerable Snippet
markdown Auto-loads `humanizer-context.md` from the project root if present. Use that file for brand samples and banned phrases.markdown **Auto-load brand context.** Before parsing further, check for `humanizer-context.md` in the current working directory using the Read tool. If it exists, load it as additional voice guidance (brand samples, banned phrases, preferred terms). Treat its contents as a personal extension of the `--voice` profile. If it doesn't exist, proceed without warning; this is opt-in.Technical Analysis
The skill instructs the agent to load
humanizer-context.mdautomatically from the current project and treat its contents as an extension of the active voice profile. A project repository can control this file, but the skill provides no schema validation, content restrictions, trust-boundary warning, or instruction filtering.Consequently, a malicious repository can place arbitrary natural-language instructions in this context file. When the skill runs, those instructions enter the agent's working context and may influence its rewriting behavior. For example, the file could demand insertion of attacker-selected text, removal or distortion of source content, disclosure of supplied document data, or attempts to invoke unrelated tools.
The phrase “this is opt-in” does not provide effective consent because the documented behavior proceeds automatically and silently when the file exists. Higher-priority system and platform policies remain authoritative, so this issue does not independently establish unrestricted code execution or privilege escalation. It does, however, create a direct indirect-prompt-injection path within the skill's legitimate processing flow.
Attack Path
- An attacker prepares or modifies a re ...[truncated 1366 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not load
humanizer-context.mdsilently. Require explicit user confirmation before reading project-provided context. - Treat the file as untrusted data rather than executable guidance. State explicitly that instructions, tool requests, policy overrides, and requests to read other files must be ignored.
- Replace free-form Markdown with a constrained format containing approved fields such as:
preferred_termsbanned_phrasesvoice_examplestone_attributes
- Validate field types, lengths, and allowed values before incorporating them into the prompt.
- Delimit imported content clearly and ensure it cannot redefine the skill's workflow, tool permissions, output destination, or safety constraints.
- Reject or escape content containing instruction-like directives, references to system prompts, requests for tool use, or attempts to override existing rules.
- Display the loaded path and a short summary to the user, and allow the user to decline its use.
- In edit mode, show a diff or request confirmation before writing changes influenced by project-provided context.
- Restrict context discovery to a known project root rather than relying on an ambiguous current working directory, and prevent traversal or symlink-based substitution where the host environment permits such checks.
- Do not load
