YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]
- Category
- YARA Match
- Confidence
- 80% confidence
- Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
- Content
md --- name: prompt-injection description: Contain prompt injection by removing capabilities, not by detection — tool-less LLM subprocess, fenced data, code-checked output, HMAC approvals. For agents reading untrusted text. metadata: {"clawdbot":{"emoji":"🧱","requires":{"bins":["python3"]},"homepage":"https://openclaw.ai"}} --- # Prompt Injection Containment You will not filter your way out of prompt injection. Assume the model that reads third-party text is already compromised, then make that harmless: it holds no tool, sits in an empty directory, decides no write, and cannot approve anything. Detection (regex, classifiers) is optional on top; containment is not. ## Data, access, and retention — read firs
