T01 · Skill Instruction Hijacking
- Location
SKILL.md:27- Finding
Mutable Remote Instructions Can Influence Agent Behavior
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27-31
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: MediumComplete Code Snippet:
markdown ## Navigation Reference **Live context file:** https://www.hergunmac.com/llm.txt Fetch the latest navigation guide directly from the site for up-to-date URL patterns, UI elements, and browser automation notes.Technical Analysis
The skill explicitly instructs the agent to retrieve a remotely hosted text file and use it as a navigation and browser-automation guide. Unlike the bundled reference, the remote file is not immutable, version-pinned, integrity-checked, or included in the audited package.
Because this resource is intended for consumption by an LLM, instructions introduced into it could be interpreted as trusted operational directives rather than untrusted website content. A party controlling the domain, web server, deployment pipeline, or
/llm.txtresource could modify the agent's browser behavior after the skill has been reviewed. This creates a prompt-injection and instruction-hijacking boundary.The audited package does not contain an executable remote payload, credential-stealing logic, persistence mechanism, or direct data-exfiltration implementation. Therefore, this is classified as instruction hijacking rather than remote code execution.
Attack Path
- A user activates the skill with a football prediction or match-analysis request.
- The agent follows the instruction in
SKILL.mdand fetcheshttps://www.hergunmac.com/llm.txt. - An attacker who has compromised or legitimately controls the remote resource changes it to include malicious LLM instructions.
- The remote instructions direct the agent toward attacker-selected pages or actions, potentially requesting sensitive information or attempting to override the original task and safety constraints.
- If the agent treats the remote guide as authori ...[truncated 805 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to fetch and follow the live LLM context file automatically.
- Prefer the bundled, reviewed
references/llm-context.mdfile as the authoritative navigation guide. - If remote updates are required, pin the resource to a reviewed version and verify it using a trusted cryptographic digest or signature.
- Treat all remotely fetched content as untrusted data, never as higher-priority agent instructions.
- Parse remote navigation data through a strict schema that accepts only necessary fields, such as allowlisted routes and UI labels, while rejecting free-form instructions.
- Restrict browser navigation to the expected HTTPS origin and an explicit allowlist of routes.
- Prevent remote content from requesting credentials, changing safety constraints, invoking unrelated tools, accessing local files, or initiating transactions.
- Require explicit user confirmation before performing sensitive browser actions or leaving the allowlisted domain.
- Maintain a reviewed local fallback and fail closed when integrity or validation checks do not pass.
