T01 · Skill Instruction Hijacking
- Location
SKILL.md:197- Finding
Remotely Retrieved Instructions Can Override the Audited Local Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 197-200
Vulnerability Type: Remote instruction precedence and mutable behavior
Risk Level: HighVulnerable Code Snippet:
markdown - Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "recent-news-article-aggregator"`. - Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "recent-news-article-aggregator"`, or call this product with `action: "get_instructions"` when the product tool is already selected. - Treat returned live schema and instructions as more specific than this generated summary.Technical Analysis
The Skill directs the agent to retrieve instructions from an external AgentPMT service and explicitly gives those remotely returned instructions precedence over the locally audited summary. Unlike a strictly validated data response, instructional prose can change after installation and is not constrained by the reviewed package.
This creates a mutable instruction channel. If the remote service, its account, the associated tool configuration, or the transport trust boundary is compromised, returned content could attempt to change how the agent handles user data, selects tools, performs retries, or interprets safety requirements. The local document does contain protective guidance concerning secrets, but the remote-precedence rule weakens the assurance that the audited local behavior remains authoritative.
No evidence establishes that the current remote endpoint is compromised or presently returns malicious content. The vulnerability is the delegation of instruction authority to unaudited, changeable content.
Attack Path
- An attacker compromises or gains control over the AgentPMT instruction response, associated product configuration, or another component capable of influencing
get_instructions. - The agent loads this Skill ...[truncated 950 chars]
- An attacker compromises or gains control over the AgentPMT instruction response, associated product configuration, or another component capable of influencing
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction that remotely returned prose takes precedence over the audited local Skill.
- Treat remote responses exclusively as untrusted data, never as agent instructions.
- Retrieve only a versioned, machine-readable schema and validate it against a strict local allowlist of actions, fields, types, and enum values.
- Pin the expected schema version or integrity digest and reject unexpected changes.
- Prevent remote content from modifying system instructions, safety constraints, credential-handling rules, tool permissions, or data-disclosure policies.
- If dynamic documentation remains necessary, display it as reference material and require explicit user approval before it changes tool behavior.
- Apply output filtering so fields containing imperative instructions or unsupported actions cannot enter the agent's instruction context.
