Back to skill

Security audit

pact0-hire

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it makes a remote, changeable pact0 document override the reviewed local instructions.

Review before installing. Do not put secrets, private data, or non-consenting personal information into pact0 jobs. The main concern is that the remote pact0 skill contract can change and override the reviewed local file, so future behavior may differ from this package.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:20
Finding

Mutable Remote Instructions Override the Audited Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–21
Vulnerability Type: Remote instruction precedence
Risk Level: High

Vulnerable snippet:

markdown
This file is a pointer: the live contract,
https://pact0.com/skill.md?src=agent-skill-hire, wins if they disagree.

Technical Analysis

The packaged Skill explicitly declares that mutable instructions hosted on pact0.com take precedence over the locally audited instructions whenever the two disagree. Consequently, the effective behavior is not bounded by the reviewed artifact.

The external service operator controls the remote document and can change it after the package has been installed or audited. HTTPS authenticates the remote server during transport, but it neither pins the document's reviewed contents nor limits which instructions it may contain.

When the Skill is used, the precedence rule can cause an agent to follow newly introduced, unaudited directions. Those directions could alter how the agent creates jobs, handles task content, uses the service API, or handles the pact0 API key. The audited repository does not contain the remote document, so its future contents cannot be verified statically.

The checked-in file does not prove that the external operator currently serves a malicious payload. This is therefore high-risk, externally mutable behavior rather than evidence of an intentional backdoor.

Attack Path

  1. A user installs or invokes the locally reviewed Skill.
  2. The agent processes the instruction stating that the remote skill.md overrides the packaged file.
  3. The operator of pact0.com changes the remote document after local review.
  4. The agent retrieves or otherwise consults that mutable document as the authoritative contract.
  5. Conflicting remote instructions supersede the audited instructions.
  6. The agent may then perform unaudited actions using task data, network access, or the service credential ava ...[truncated 643 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the statement granting precedence to the remote document.
  2. Store the complete authoritative contract in the reviewed Skill package.
  3. If remote updates are operationally necessary, retrieve only a versioned artifact pinned by a cryptographic digest or verified signature.
  4. Treat remotely retrieved documents as untrusted data rather than executable agent instructions.
  5. Display behavior-changing updates to the user and require explicit approval before applying them.
  6. Constrain authenticated requests to a fixed allowlist of documented endpoints and ensure remote content cannot redefine credential handling, disclosure rules, or authorization boundaries.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
add `"rubric"` inside `acceptance_criteria` to say what you will check. The
response's `data.id` is your job id.

Write it so a stranger can finish it without asking you anything: give the
input, say what "done" means, and ask for evidence (links, transcripts,
exact calls). Jobs are public, so never include secrets, private data or
anything about a person who did not agree to it.

Static analysis

No suspicious patterns detected.