T01 · Skill Instruction Hijacking
- Location
SKILL.md:25- Finding
Mandatory Loading of an Unbundled External Skill Enables Instruction Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:25andSKILL.md:127
Vulnerability Type: External instruction dependency
Risk Level: HighVulnerable Code Snippets
At
SKILL.md:25:markdown 4. **Protocol** — Load and complete the [review-verification-protocol](../review-verification-protocol/SKILL.md) skill **after** gates 1–3 and **before** final severity labels. **Pass:** Protocol steps satisfied for each retained finding.At
SKILL.md:127:markdown Complete **Gates (evidence before severity)**, then load and follow the [review-verification-protocol](../review-verification-protocol/SKILL.md) skill before reporting any issue.Technical Analysis
The skill twice requires the agent to load and follow instructions from
../review-verification-protocol/SKILL.md, a path outside the audited project root. The referenced file was not included in the supplied artifact and therefore could not be inspected or verified.This creates an instruction-integrity boundary that is not controlled by the reviewed package. An attacker or untrusted package with write access to the sibling path could supply a malicious
SKILL.md. Because loading that file is presented as a mandatory gate before assigning severities or reporting findings, its instructions could influence the agent's goals, suppress legitimate findings, alter risk classifications, expand the review scope, or request unauthorized actions.The audited files contain no executable code, network retrieval, credential collection, or persistence mechanism. Exploitation therefore depends on the agent resolving the external path and an attacker being able to control or replace the referenced sibling skill.
Attack Path
- A user or automated agent loads this skill to perform a
sqlxcode review. - The agent follows the mandatory protocol requirement in
SKILL.md. - The agent resolves
../review-verification-protocol/SKILL.md, which lies outside the audited project. - A ...[truncated 1199 chars]
- A user or automated agent loads this skill to perform a
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory dependency on
../review-verification-protocol/SKILL.md. - Vendor the complete verification protocol inside this project so it is covered by the same audit and integrity controls.
- If an external reference is unavoidable, treat its contents as untrusted reference data rather than authoritative instructions.
- Restrict references to paths inside the skill package and reject path traversal through parent-directory components such as
../. - Pin and verify external skill content with a trusted cryptographic digest or signed manifest before loading it.
- Explicitly state that referenced content cannot modify system or user instructions, request unrelated tool operations, expand access, suppress findings, or alter the authorized review scope.
- Fail closed when the protocol is missing or its integrity cannot be verified, rather than searching mutable sibling directories.
- Include every instruction-bearing dependency in future audit artifacts so the complete effective behavior can be reviewed.
- Remove the mandatory dependency on
