T01 · Skill Instruction Hijacking
- Location
SKILL.md:280- Finding
Mutable Remote Instructions Are Treated as Authoritative
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 280-285
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: MediumVulnerable Code Snippet:
markdown ## Live Schema And Examples Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first. - Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "color-adjustment"`. - Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "color-adjustment"`, or call this product with `action: "get_instructions"` when the product tool is already selected. - Treat returned live schema and instructions as more specific than this generated summary.Technical Analysis
The Skill delegates authority to mutable instructions retrieved from an external AgentPMT service. In particular, it tells the agent to treat returned live instructions as more specific than the locally reviewed Skill definition.
The text does not require the agent to:
- Treat remote instructions as untrusted data.
- Restrict remote responses to declarative schema fields.
- Reject instructions unrelated to color processing.
- Validate responses against a pinned local schema.
- Preserve local security constraints when remote instructions conflict with them.
- Verify a version, signature, or content hash.
Consequently, the effective behavior can change after the local Skill has been audited. A compromised, malicious, or incorrectly configured remote service could return instruction-like content that attempts to redirect the agent's behavior.
Attack Path
- An attacker compromises the AgentPMT service, its response pipeline, or an upstream account capable of modifying the returned tool instructions.
- The agent invokes `get_instr ...[truncated 992 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat all remotely returned schemas, examples, and instructions as untrusted data rather than authoritative agent directives.
- Replace the precedence statement with an explicit rule that local platform policies, safety constraints, and the reviewed Skill definition always take priority.
- Parse remote schema responses into a strict allowlisted data structure containing only expected action names, parameter types, bounds, and descriptions.
- Reject responses containing executable commands, requests for credentials, unrelated tool calls, new endpoints, or behavioral instructions outside color processing.
- Pin remote documentation to an approved version or verify a publisher signature or content digest before use.
- Require explicit user approval before honoring any remote change that expands data transmission, permissions, endpoints, payment behavior, or tool scope.
- Prefer the bundled
schema.mdfor normal operation and use remote lookup only when the user explicitly requests updated schema information.
