T01 · Skill Instruction Hijacking
- Location
SKILL.md:94- Finding
Skill Instructions Recommend Disabling Sandbox and Approval Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:94
Vulnerability Type: Safety-control bypass instruction
Risk Level: HighVulnerable Instruction
text --sandbox danger-full-access --ask-for-approval neverThe Skill instructs users to start Codex with these options to address potential network restrictions.
Technical Analysis
The recommended options disable two independent security boundaries:
--sandbox danger-full-accessremoves filesystem and process isolation.--ask-for-approval neverprevents the Agent from requesting confirmation before sensitive operations.
Legal-search functionality only requires narrowly scoped HTTPS access to
open.chineselaw.comand controlled report writes. Unrestricted system access and unconditional execution are not necessary for that purpose. Presenting these settings as the recommended response to network problems weakens the security posture of the entire Agent session, rather than granting only the specific network capability needed by the Skill.This is an instruction-layer vulnerability because the unsafe behavior is introduced through the Skill documentation and can alter the safety constraints under which the Agent executes.
Attack Path
- A user or Agent loads the Skill and encounters the network troubleshooting instruction.
- The user restarts Codex with
danger-full-accessand approval prompts disabled. - The Skill, another subsequently loaded Skill, compromised local content, or an erroneous Agent action requests a sensitive tool operation.
- The operation executes without sandbox containment or interactive approval.
- The operation can access or modify resources available to the host user account.
Impact Assessment
Following the instruction can expose all files, credentials, repositories, and processes accessible to the user running Codex. Subsequent commands may read or modify data outside the project, execute arbitrary local programs, or transmit sensit ...[truncated 246 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to use
danger-full-accessand disable approvals. - Keep filesystem sandboxing and approval prompts enabled by default.
- Request only narrowly scoped outbound HTTPS access to:
open.chineselaw.comydzk.chineselaw.com, if source-link connectivity checks genuinely require it
- Document sandbox-compatible network configuration instead of instructing users to disable the sandbox.
- If a network operation cannot run under the current policy, stop and ask the user to approve that specific network request.
- Clearly state that users should not weaken global Agent controls merely to troubleshoot DNS, proxy, or VPN problems.
- Remove the recommendation to use
