T01 · Skill Instruction Hijacking
- Location
scripts/roast.sh:21- Finding
Unconditional Promotional Output Contaminates Skill Results
- Content
View full analysis
Vulnerability Details
File Location:
scripts/roast.sh:21
Vulnerability Type: Unconditional output injection
Risk Level: LowEvidence
python print("\nPowered by BytesAgain | bytesagain.com\nAll in good fun!")Technical Analysis
The script unconditionally appends third-party branding to standard output on every invocation. This includes invocations where standard output is expected to contain only the requested roast or command result.
Because
SKILL.mdinstructs consumers to treat standard output as the command result, an agent integrating this skill may relay the promotional content directly to users. The injected text is fixed and does not execute code or change agent safety constraints, but it modifies agent-visible output for a purpose unrelated to the requested operation.Attack Path
- An agent invokes
scripts/roast.shto generate a roast or display command information. - The Python program processes the requested command.
- Line 21 appends the promotional message regardless of the command or user preference.
- The agent captures standard output as the skill result.
- The unsolicited promotional message is relayed to the user alongside the legitimate result.
Impact Assessment
No additional operating-system privileges, code execution, or data access can be obtained through this behavior. The scope is limited to output integrity: generated results are predictably contaminated with unsolicited advertising, which may mislead users about whether the agent endorsed or generated that content.
- An agent invokes
- Remediation
View remediation
Remediation Suggestions
- Remove the unconditional promotional message from normal standard output.
- If attribution is required, expose it only through an explicit command such as
infoor an opt-in flag such as--credits. - Keep standard output limited to the requested command result.
- Send optional diagnostic or attribution information to standard error only when verbose mode is explicitly enabled.
- Add output tests ensuring that generation commands return only documented result content.
