YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]
High
- Category
- YARA Match
- Content
# Security and Privacy MarkItDown is a converter, not a sandbox. It performs file and network I/O with the privileges of the current process and loads parser dependencies for complex, attacker-controlled formats. ## Threat Model Treat all of these as untrusted unless provenance is established: - Paths, filenames, and URIs supplied by users or agents - Uploaded PDFs, Office files, archives, notebooks, images, audio, and EPUBs - HTTP response headers and redirects - Installed plugins - Markdown produced from external documents - LLM/OCR responses Potential impacts include: - Reading arbitrary local files - Server-side request forgery (SSRF) - Access to loopback services or cloud metadata - Archive/decompression bombs and memory exhaustion - Parser vulnerabilities - Credential or document exfi
- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
