T01 · Skill Instruction Hijacking
- Location
src/sources/contextComposer.js:41- Finding
Untrusted Local and Remote Content Is Inserted into AI Context Without Prompt-Injection Controls
- Content
View full analysis
50 ? '🔥' : w.score > 10 ? '⭐' : '📗'; const answered = w.isAnswered ? '✅' : '❓'; sections.push(`\n${votes} ${answered} [${w.title}](${w.url})`); sections.push(` Score: ${w.score} | Answers: ${w.answerCount} | Tags: ${w.tags?.slice(0, 3).join(', ')}`); } sections.push(''); } ``` The untrusted values originate from local project files and Stack Overflow: ```javascript const content = fs.readFileSync(fullPath, 'utf-8'); ``` ```javascript const soResponse = await fetch(`${STACKOVERFLOW_API}?${soParams}`); const soData = await soResponse.json(); ``` ### Technical Analysis SCG generates context intended for consumption by an AI coding assistant. Local file contents and remote Stack Overflow metadata are attacker-controllable, but they are inserted into the generated context without sanitization, trust-boundary labels, instruction filtering, or a structured separation between instructions and reference data. Markdown code fences do not constitute a dependable security boundary for language models. A model may interpret natural-language instructions contained in source comments, Markdown files, JSON values, filenames, or remote question titles as ...[truncated 2034 chars]- Remediation
View remediation
