T09 · Insecure Skill Coding Practices
- Location
infra/agents/web-scribe.prompt.ts:236- Finding
Untrusted Web Content Is Processed by a Shell-Capable Autonomous Agent Without Prompt-Injection Isolation
- Content
View full analysis
Vulnerability Details
File Location:
infra/agents/web-scribe.prompt.ts, lines 236–257 and 292–297
Vulnerability Type: Indirect prompt injection through externally controlled web content
Risk Level: MediumRelevant code:
typescript ## 4. Seed what is empty Only for domains step 3 found empty, from the page files and the news: - global/: positioning, value proposition, and offerings (what is sold, to whom, at what pricing shape). One file each. - icp/: who the pages say the product is for, as one file tagged inferred, with at least one disqualifier: a company that looks like a fit and is not. The CRM verifies it later; say so in the file's Source section. - alternative/: one file per competitor the pages, the news or COMPETITORS name, plus one for the status quo (what buyers do without any product). - client/: one file per customer named on the pages, with the industry, size and use case the page states, and reference_permission: unknown. - proof/: one file per atomic proof point on those pages (a metric, a quote, a result), citing its client/ file and the URL. confidence: hypothesis. - signal/: one candidate per event that would make a company likely to buy, as the pages describe their buyers, with its detection written operationally. confidence: hypothesis. Do not write persona/ or jtbd/: job titles and jobs come from evidence this cookbook does not read.typescript Otherwise write outputs/<today>-web-capture/README.md with the frontmatter that layer requires (its outcome: line reads "web capture: <n> files added"), run the repository's context lint (npm run lint:context) and fix what it reports, then open one branch and one pull request titled "[web-capture] <first run | week of <today>>", committing the page, competitor and news files with the context files. Do not merge it, and do not push to the default branch....[truncated 3333 chars]
- Remediation
View remediation
Remediation Suggestions
- Add an explicit, high-priority rule stating that all page and news content is untrusted data and that instructions, commands, tool requests, or policy text contained within it must never be followed.
- Parse extraction results into a strict schema and provide the synthesis stage only the fields required for analysis rather than unrestricted full-page content.
- Separate retrieval and interpretation from command execution. A non-agent helper should validate and write raw content, while a restricted synthesis step should produce only structured candidate findings.
- Enforce filesystem boundaries outside the model so that generated changes can only target approved paths such as
context/,cadence/log/raw/web/, and the designated output directory. - Replace general shell access with an allowlisted command interface. Permit only the exact Cargo, Git, lint, and pull-request operations required by the workflow.
- Validate the resulting diff before any push and reject modifications outside the approved path set or changes to existing protected context files.
- Run external-content processing in a sandbox without unrelated credentials, network access, or host filesystem access.
- Preserve mandatory human review and supplement it with automated checks that block unexpected executable files, workflow changes, configuration changes, or command-bearing output.
