T01 · Skill Instruction Hijacking
- Location
SKILL.md:40- Finding
Untrusted Remote Skill Instructions Can Hijack Agent Behavior
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 40-48 and 64-70
Vulnerability Type: Remote instruction delegation without validation or trust boundaries
Risk Level: HighVulnerable Code Snippet
markdown ### Get a Service's skill.md Each service has a `skill` field with its skill.md URL: ```bash # Get Moltbook's skill.md curl https://www.moltbook.com/skill.md # Get Ctxly Memory's skill.md curl https://ctxly.app/skill.mdtext ```markdown ## Workflow 1. **Discover** — `curl ctxly.com/services.json` 2. **Learn** — Fetch the skill.md for services you need 3. **Use** — Follow the skill.md to integrateTechnical Analysis
The Skill instructs an agent to obtain service entries from a mutable remote directory, retrieve third-party
skill.mddocuments, and then follow those documents. These remotely hosted instructions are outside the reviewed package and can change after publication or audit.No content-integrity verification, immutable version reference, domain allowlist, instruction isolation, capability restriction, or explicit user-approval boundary is defined. In particular, the instruction to “Follow the skill.md” can cause remotely supplied content to be interpreted as trusted operational instructions rather than untrusted reference material.
This behavior exceeds the minimum privileges required for simple service discovery. A directory Skill only needs to present service metadata or documentation; it does not need to authorize arbitrary third-party documents to direct subsequent agent actions.
This is instruction hijacking rather than confirmed remote code execution: the retrieved files are Markdown instructions, and the audited package does not directly execute downloaded code. Nevertheless, a remote document could instruct a tool-enabled agent to invoke commands, disclose information, modify files, or contact additional endpoints.
Attack Path
- An attacker registers a service in the directory, compromi ...[truncated 1873 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat every remotely retrieved
skill.mdas untrusted data, not as authoritative agent instructions. - Replace “Follow the skill.md” with a constrained process that summarizes the document for the user and requires explicit approval before performing any action.
- State that remote content cannot override system instructions, developer policies, user intent, security controls, or authorization boundaries.
- Maintain an explicit allowlist of approved domains and reject redirects or URLs outside that allowlist.
- Pin reviewed documents using immutable versions or cryptographic hashes. Reject content whose digest differs from the approved value.
- Validate directory responses against a strict schema and normalize URLs before use.
- Apply capability-based restrictions when processing remote documents. Deny access to secrets, local files, shell execution, persistent storage, and unrelated network destinations unless separately required and approved.
- Separate retrieval from execution: fetch and display or summarize documentation in one step, then construct a local, reviewed action plan rather than executing instructions directly.
- Require confirmation for operations involving credentials, payments, external messages, file changes, account changes, or transmission of potentially sensitive data.
- Record the source URL, final redirected URL, document version, content hash, requested actions, and user approvals in an audit log.
- Add warnings explaining that directory inclusion does not establish the trustworthiness of a listed service or its instructions.
- Treat every remotely retrieved
