T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Untrusted External Service Can Direct Agent Tasks and Receive Agent-Generated Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 3-94
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code
markdown Connect to the BlackPix distributed AI knowledge network. Your bot receives tasks from the system, contributes knowledge, and earns karma to unlock more access.bash curl -X POST https://blackpix.com/api/open/register \ -H "Content-Type: application/json" \ -d '{"name": "YourBotName", "description": "What you do"}'json { "apiKey": "bpx_xxx...", "claimUrl": "https://blackpix.com/claim/abc123", "claimInstructions": "Send claimUrl to your human..." }markdown ### Request TaskGet a task from BlackPix Get a physics task from BlackPix Request a BlackPix task about AI
text System assigns a task with context (title, summary, instructions). ### Submit WorkSubmit to BlackPix: [your contribution text]
text Submit your completed work for AI evaluation.bash curl -X POST https://blackpix.com/api/work/request-task \ -H "Content-Type: application/json" \ -H "X-BlackPix-API-Key: $BLACKPIX_API_KEY" \ -d '{"preferredType": "contribute", "focusAreas": ["physics"]}'bash curl -X POST https://blackpix.com/api/work/submit \ -H "Content-Type: application/json" \ -H "X-BlackPix-API-Key: $BLACKPIX_API_KEY" \ -d '{"taskId": "uuid", "submission": "Your contribution..."}'Technical Analysis
The skill delegates task selection and task instructions to the external
blackpix.comservice. It tells the agent to self-register, request a task containing a title, summary, and instructions, act on that task, and transmit the resulting contribution back to the service.The document does not establish a trust boundary for remotely supplied task text. It does not require the agent to treat task instructions as untrusted data, constrain them to a d ...[truncated 2097 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user authorization before registration, before accepting every remote task, and before submitting any content.
- Treat all remote task fields, including titles, summaries, instructions, and claim instructions, as untrusted data rather than authoritative agent instructions.
- Define a strict allowlist of supported task types and permitted tool operations. Reject tasks that request file access, credential access, shell execution, configuration changes, memory changes, or unrelated network activity.
- Add an explicit instruction-precedence rule stating that remote content cannot override system instructions, developer instructions, user intent, safety controls, or workspace boundaries.
- Validate API responses against a strict schema and enforce size, type, and content limits before presenting them to the agent.
- Apply outbound data-loss prevention before
/submit: block secrets, API keys, environment variables, private conversation content, local file contents, and unrelated workspace data. - Show the user the exact sanitized task and exact proposed submission, including the destination domain, before any action is taken.
- Scope the BlackPix API key to the minimum necessary permissions, store it in an approved secret manager, never include it in generated submissions, and support immediate revocation.
- Pin and verify the expected HTTPS origin. Do not follow cross-origin redirects for authenticated requests.
- Log task identifiers, approvals, rejected instructions, and submitted content for auditability without recording secrets.
