Back to skill

Security audit

Luke Agent Directory

Security checks for vulnerabilities and agentic risk

Overview

This directory skill is mostly transparent, but it tells agents to fetch and follow mutable third-party skill instructions without clear trust boundaries or user approval.

Install only if you are comfortable using it as a service directory. Treat any fetched skill.md as untrusted documentation, review it before acting, and require explicit approval before commands, file changes, credential use, account changes, payments, or data sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:40
Finding

Untrusted Remote Skill Instructions Can Hijack Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 40-48 and 64-70
Vulnerability Type: Remote instruction delegation without validation or trust boundaries
Risk Level: High

Vulnerable Code Snippet

markdown
### Get a Service's skill.md

Each service has a `skill` field with its skill.md URL:

```bash
# Get Moltbook's skill.md
curl https://www.moltbook.com/skill.md

# Get Ctxly Memory's skill.md
curl https://ctxly.app/skill.md
text

```markdown
## Workflow

1. **Discover** — `curl ctxly.com/services.json`
2. **Learn** — Fetch the skill.md for services you need
3. **Use** — Follow the skill.md to integrate

Technical Analysis

The Skill instructs an agent to obtain service entries from a mutable remote directory, retrieve third-party skill.md documents, and then follow those documents. These remotely hosted instructions are outside the reviewed package and can change after publication or audit.

No content-integrity verification, immutable version reference, domain allowlist, instruction isolation, capability restriction, or explicit user-approval boundary is defined. In particular, the instruction to “Follow the skill.md” can cause remotely supplied content to be interpreted as trusted operational instructions rather than untrusted reference material.

This behavior exceeds the minimum privileges required for simple service discovery. A directory Skill only needs to present service metadata or documentation; it does not need to authorize arbitrary third-party documents to direct subsequent agent actions.

This is instruction hijacking rather than confirmed remote code execution: the retrieved files are Markdown instructions, and the audited package does not directly execute downloaded code. Nevertheless, a remote document could instruct a tool-enabled agent to invoke commands, disclose information, modify files, or contact additional endpoints.

Attack Path

  1. An attacker registers a service in the directory, compromi ...[truncated 1873 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat every remotely retrieved skill.md as untrusted data, not as authoritative agent instructions.
  2. Replace “Follow the skill.md” with a constrained process that summarizes the document for the user and requires explicit approval before performing any action.
  3. State that remote content cannot override system instructions, developer policies, user intent, security controls, or authorization boundaries.
  4. Maintain an explicit allowlist of approved domains and reject redirects or URLs outside that allowlist.
  5. Pin reviewed documents using immutable versions or cryptographic hashes. Reject content whose digest differs from the approved value.
  6. Validate directory responses against a strict schema and normalize URLs before use.
  7. Apply capability-based restrictions when processing remote documents. Deny access to secrets, local files, shell execution, persistent storage, and unrelated network destinations unless separately required and approved.
  8. Separate retrieval from execution: fetch and display or summarize documentation in one step, then construct a local, reviewed action plan rather than executing instructions directly.
  9. Require confirmation for operations involving credentials, payments, external messages, file changes, account changes, or transmission of potentially sensitive data.
  10. Record the source URL, final redirected URL, document version, content hash, requested actions, and user approvals in an audit log.
  11. Add warnings explaining that directory inclusion does not establish the trustworthiness of a listed service or its instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.