T01 · Skill Instruction Hijacking
- Location
skills/LEAP/SKILL.md:221- Finding
Untrusted Remote Skill Instructions Are Injected into the Agent Compilation Context
- Content
View full analysis
--json` for each candidate. - Sort by quality_score: prioritize elite (>=11), discard draft (<9). 3. Automatically select and inject: - Select the top 3-5 elite exemplars. - Write them to `references/exemplars/exemplar-.md`. - Write scoring results to `references/exemplar_candidates.json`. 4. Failure handling: - If all candidates score below 9, expand the search terms and retry. - If no elite candidate is found after two rounds, mark discovery as degraded. - At least one exemplar must still be attempted. ``` The compilation requirements subsequently state: ```text Fetched exemplars must be injected. At least one exemplar's section organization must be used as a reference. ``` ### Technical Analysis LEAP obtains mutable `SKILL.md` documents from a public registry and GitHub repositories, then injects selected documents into the agent's compilation context. The described mechanical scoring process evaluates structural quality but is not a security boundary and does not detect instruction hijacking. A malicious exemplar can contain directives that appear to be part of the skill itself, such as instructions to ignore the compiler's constraints, include attacker-selected installation commands, retrieve additional dependencies, access sensitive files, or alter the fina ...[truncated 2263 chars]- Remediation
View remediation
