T01 · Skill Instruction Hijacking
- Location
SKILL.md:147- Finding
Mutable Remote Instructions Are Given Precedence Over the Locally Audited Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 147–149
Vulnerability Type: Remote instruction injection and trust-boundary violation
Risk Level: Mediumtext - Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "climate-environmental-data"`. - Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "climate-environmental-data"`, or call this product with `action: "get_instructions"` when the product tool is already selected. - Treat returned live schema and instructions as more specific than this generated summary.Technical Analysis
The Skill instructs the Agent to retrieve mutable instructions from an external AgentPMT service and treat the returned content as more specific than the locally reviewed Skill. This establishes a remote instruction channel whose effective behavior can change after installation and static audit.
Retrieving a current schema is reasonable for compatibility, but allowing remotely supplied instructions to take precedence is not required merely to query climate data. Remote content should be treated as untrusted data and validated against locally defined actions and parameter constraints. The Skill does not explicitly authorize remote content to override higher-level safety requirements, so this is not evidence of an active malicious payload; nevertheless, the precedence rule creates a viable instruction-hijacking boundary.
Attack Path
- An attacker compromises the AgentPMT service, its infrastructure, an authorized publishing account, or another component capable of modifying the
get_instructionsresponse. - The Agent follows the Skill and calls
get_instructionsforclimate-environmental-data. - The service returns attacker-controlled behavioral instructions alongside legitimate-looking tool documentation.
- The local Skill directs the Agent to treat tho ...[truncated 844 chars]
- An attacker compromises the AgentPMT service, its infrastructure, an authorized publishing account, or another component capable of modifying the
- Remediation
View remediation
Remediation Suggestions
- Treat responses from
get_schemaandget_instructionsas untrusted data, not authoritative Agent instructions. - Remove the statement that returned instructions are more specific than the local Skill.
- State explicitly that remote responses cannot override system, developer, user, authorization, privacy, or security constraints.
- Validate remote schemas against a local allowlist containing only the
query_climate_dataaction and its documented parameters. - Reject remote responses that introduce new actions, external destinations, credential requests, local command execution, or unrelated tool calls.
- Pin and verify a schema version or signed schema digest for production integrations.
- Require user confirmation before following any remotely introduced behavior that expands data disclosure or tool usage.
- Treat responses from
