T01 · Skill Instruction Hijacking
- Location
SKILL.md:137- Finding
Untrusted GitHub Content Can Hijack Autonomous Repository Workers
- Content
View full analysis
`. - required proof and PR body. - notification route. Worker instructions: ```text Use gh and git. Do not handwave. Checkout/create fix/issue- from BASE_BRANCH. Implement minimal fix. Run relevant tests. Commit with conventional message. Push to PUSH_REMOTE. Open PR against SOURCE_REPO BASE_BRANCH. PR body: What Problem This Solves + Why This Change Was Made + User Impact + Evidence + visible Fixes SOURCE_REPO#. Report PR URL or failure reason. Send completion/failure with openclaw message send if route provided. ``` ``` The review workflow contains the same trust-boundary issue: ```markdown Fetch review threads/comments: ```bash gh pr view --repo "$SOURCE_REPO" --json url,headRefName,comments,reviews gh api "repos/$SOURCE_REPO/pulls//comments" gh api "repos/$SOURCE_REPO/issues//comments" ``` Only process `fix/issue-*` PRs created by this workflow unless the user explicitly named PR numbers. Group actionable comments by PR. Ignore praise, status, duplicates, and already-addressed comments. Spawn one worker per selected/scoped PR, same background rules. Review worker instructions: ```text Checkout PR branch. Read all actionable review comments. Patch minimal changes. Run relevant tests. Commit and push normally; do not force-push unless explicitly told. Reply to addressed comments with fix + commit/file reference. Report comments addressed/skipped and proof. ``` ``` ### Technical Analysis The Skill requires issue titles, bodies, labels, and review comments to be placed into autonomous worker context. Th ...[truncated 3102 chars]- Remediation
View remediation
