T01 · Skill Instruction Hijacking
- Location
SKILL.md:66- Finding
Untrusted Web-Derived Content Is Recursively Injected into Agent Prompts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a transparent debate-research skill that uses subagents and web search for its stated purpose, with manageable prompt-injection and installer-version risks users should understand.
Before installing, consider pinning the ClawHub installer version instead of using @latest. When using the skill on consequential topics, verify important sources yourself because web content and earlier agent outputs are reused in later debate phases and could bias the final report.
SKILL.md:66Untrusted Web-Derived Content Is Recursively Injected into Agent Prompts
README.md:55Installation Documentation Executes a Mutable Latest Package Release
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
Do NOT judge who is right or wrong. Only audit evidence quality.
The install command uses npx clawhub@latest, which fetches and executes the latest published package rather than a pinned, reviewed version. If the package is compromised, a malicious release is published, or the publisher account is hijacked, users installing the skill could execute attacker-controlled code during setup.
No suspicious patterns detected.