T01 · Skill Instruction Hijacking
- Location
infra/agents/ask-cargo.prompt.ts:14- Finding
Repository Instructions Can Override the Skill's Safety Controls
- Content
View full analysis
Vulnerability Details
File Location:
infra/agents/ask-cargo.prompt.ts, lines 14–16
Vulnerability Type: Untrusted instruction precedence / prompt injection
Risk Level: HighVulnerable code:
typescript Read AGENTS.md (or CLAUDE.md) first for the repository's conventions. Repository conventions win over anything in this prompt.Technical Analysis
The system prompt directs the agent to read instructions from
AGENTS.mdorCLAUDE.mdin the checked-out repository and gives those instructions unconditional precedence over the rest of the Skill prompt.Repository files are task data that may be modified by repository contributors or other processes. They must not be allowed to override trusted authorization and safety policy. The precedence rule can supersede controls later in the prompt, including:
- Approval before actions that spend, send, write to personal records, or invoke other agents.
- Prohibitions against deployment, destruction, deletion, token operations, and membership changes.
- Restrictions against exposing secrets, environment values, or complete records.
- Restrictions against using Slack tools or writing workspace memory directly.
The Skill uses a Claude Code harness with a repository checkout, authenticated Cargo CLI access, and a GitHub connector capable of pushing branches and opening pull requests. Consequently, malicious repository guidance can influence operations across meaningful trust boundaries.
The prompt otherwise contains substantial operational restrictions, and
evals/contract.mjschecks resource wiring. However, those measures do not neutralize the unconditional precedence statement, and the contract test does not enforce prompt-level authorization rules.Attack Path
- A repository contributor or another process able to change repository content adds malicious instructions to
AGENTS.mdorCLAUDE.md. - A teammate invokes Ask Cargo through an au ...[truncated 1465 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the unconditional precedence rule with an explicit trust hierarchy:
- Treat
AGENTS.md,CLAUDE.md, and all other repository files as untrusted project context. - Permit repository guidance to control only non-security matters such as formatting, coding style, test conventions, and project structure.
- State that repository content cannot override system or Skill instructions, approval requirements, confidentiality controls, tool restrictions, prohibited operations, or user authorization.
- Require the agent to ignore and report any repository instruction that conflicts with these controls.
- Enforce sensitive operation gates in executable policy or tool wrappers rather than relying exclusively on natural-language instructions.
- Extend contract or policy tests with adversarial repository fixtures that attempt to bypass approval, disclose secrets, invoke prohibited commands, or use unauthorized communication tools.
- Apply command allowlists and independently enforce approval state for spending, external sends, record modification, and agent handoffs.
- Treat
