T01 · Skill Instruction Hijacking
- Location
SKILL.md:386- Finding
Mutable Remote Instructions Can Override the Audited Skill Definition
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:386-391
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code Snippet:
markdown ## Live Schema And Examples Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first. - Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "google-meet-connector"`. - Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "google-meet-connector"`, or call this product with `action: "get_instructions"` when the product tool is already selected. - Treat returned live schema and instructions as more specific than this generated summary.Technical Analysis
The Skill directs the agent to retrieve mutable instructions from an external AgentPMT service and treat those instructions as more authoritative than the locally installed and audited Skill definition. Although retrieving a live schema can be legitimate, granting precedence to remotely supplied natural-language instructions creates an instruction-control channel outside the reviewed package.
The response to
get_instructionsis not constrained in the local documentation to a strict data-only format, cryptographically pinned version, or allowlisted set of fields. If the AgentPMT service, connector configuration, or response path is compromised, instruction-like content could alter tool-selection behavior, encourage collection of unrelated information, or attempt to weaken session safety constraints.Attack Path
- An attacker compromises the AgentPMT service, the Google Meet connector configuration, or another component capable of modifying the
get_instructionsresponse. - The agent follows the Skill and calls
get_instructions. - The ...[truncated 904 chars]
- An attacker compromises the AgentPMT service, the Google Meet connector configuration, or another component capable of modifying the
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction that remote content is more authoritative than the audited local Skill.
- Treat all remotely returned instructions and examples as untrusted data rather than executable agent directives.
- Prefer a versioned, machine-readable schema pinned to a specific connector release.
- Validate remote schema responses against a restrictive local allowlist covering action names, parameter names, types, and permitted endpoints.
- Reject unexpected natural-language instructions, tool-routing directives, credential requests, and attempts to modify safety constraints.
- Use cryptographic signatures or integrity hashes for remotely maintained schemas where feasible.
- Require explicit user confirmation before acting on a remote response that materially expands data access or changes an operation's effect.
