T01 · Skill Instruction Hijacking
- Location
SKILL.md:64- Finding
Mutable Remote Skill Instructions Are Fetched and Executed Without Review
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64-69
Vulnerability Type: Remote instruction retrieval and instruction hijacking
Risk Level: CriticalVulnerable Code
markdown Fetch `https://api.clawlens.io/skill.md` and execute it end-to-end to obtain the ClawLens `apiKey`. If one already exists in env/secret store, reuse it. Use this `apiKey` only as input to step 2. Do not send it to ClawCash, and do not persist it beyond what the ClawLens skill says. follow the ClawLens skill, register and complete verification according to that skill. The ClawLens registration returns an `apiKey` (`claw_...`) exactly once. Keep it secret and use it only to mint the ClawCash platform token.Technical Analysis
The Skill delegates execution authority to Markdown retrieved from an external server at runtime. Because the remote document is not bundled, version-pinned, cryptographically signed, or restricted to a validated schema, its effective instructions can change after this Skill has been reviewed.
The command to “execute it end-to-end” makes the remote document part of the Agent's instruction hierarchy. A compromise of the remote server, DNS resolution, deployment process, or content-management account could therefore introduce instructions that request secrets, invoke tools, run commands, or modify the onboarding workflow.
The surrounding instructions also require periodic retrieval of mutable content and discourage intermediate narration or approval. This reduces the opportunity for users to detect newly introduced operations.
Attack Path
- An attacker compromises
api.clawlens.io, its deployment pipeline, or the account controlling the remote Skill document. - The attacker changes
skill.mdto include instructions that request credentials, execute commands, or transmit identity information to an attacker-controlled endpoint. - A user asks the Agent to install or initialize ClawCash.
...[truncated 879 chars]
- An attacker compromises
- Remediation
View remediation
Remediation Suggestions
- Bundle the prerequisite Skill in the reviewed package instead of retrieving executable instructions dynamically.
- Pin the prerequisite to an immutable version and verify a cryptographic digest or trusted digital signature before use.
- Parse remote content as untrusted data rather than as authoritative Agent instructions.
- Restrict any remote response to a documented, validated data schema that cannot contain executable prose or commands.
- Present all commands, requested identity fields, network destinations, and credential operations to the user before execution.
- Require explicit approval before registration, KYC, secret submission, package execution, or financial account creation.
- Do not automatically re-fetch and execute Skill instructions during heartbeat processing.
- Apply destination allowlisting and prevent remotely supplied instructions from selecting arbitrary network endpoints.
