T01 · Skill Instruction Hijacking
- Location
SKILL.md:180- Finding
Mutable Remote Instructions Override the Locally Audited Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 180–181
Vulnerability Type: Remote instruction precedence and instruction hijacking
Risk Level: HighVulnerable code snippet:
text - Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "infrastructure-urban-development"`, or call this product with `action: "get_instructions"` when the product tool is already selected. - Treat returned live schema and instructions as more specific than this generated summary.Technical Analysis
The Skill instructs the agent to retrieve mutable instructions from an external AgentPMT service and treat the returned content as more authoritative than the locally installed and audited Skill summary. This establishes a remote instruction-hijacking channel: the effective behavior can change after package review without any corresponding modification to the local files.
Remote schemas may legitimately be needed to maintain API compatibility, but behavioral instructions returned by a service must not override local safety rules or define new actions. The response should instead be handled as untrusted data and constrained by a locally defined, versioned schema and action allowlist.
Attack Path
- An agent loads the locally audited Skill.
- The agent encounters an unclear parameter, response, or example and invokes
get_instructionsas directed. - The AgentPMT account, service, delivery infrastructure, or returned product instructions are compromised or maliciously changed.
- The remote response contains behavioral directives that differ from the reviewed Skill.
- Because line 181 explicitly gives the remote instructions greater specificity, the agent follows the altered directives.
- The attacker can induce unauthorized tool calls, redirect data to other endpoints, request unnecessary sensitive inputs, or manipulate subsequent workflow decisions, ...[truncated 888 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the directive that remote instructions are more authoritative than the locally audited Skill.
- Bundle a versioned action schema and approved examples with the Skill.
- If live schema retrieval is necessary, treat the response strictly as untrusted structured data rather than executable agent instructions.
- Validate remote responses against a local JSON schema, including an allowlist of action names, fields, types, endpoint hosts, and acceptable values.
- Reject remote content that requests new tools, different endpoints, credentials, local file access, command execution, or changes to safety constraints.
- Pin remote schema versions and verify signed content or integrity hashes before use.
- Require explicit user approval before any remotely suggested operation that expands data disclosure, cost, or privileges.
- Ensure system and local Skill safety rules always take precedence over service-returned content.
