T01 · Skill Instruction Hijacking
- Location
scripts/vault_cleanroom.py:59- Finding
Unvalidated Telegram Chat ID Enables Clean-Room Prompt Injection
- Content
View full analysis
str: _validate_inputs(sender_id, totp_code) """ Returns the task prompt for the vault sub-agent. """ ``` The unvalidated value is subsequently embedded directly into the generated task: ```python return f"""You are the TARS Vault clean-room agent. Your job: manage an open vault session with total isolation from the main TARS session. SETUP (do this first): 1. Run this command to open the vault: {venv_py} {vault_py} open {sender_id} {totp_code} 2. Send the output DIRECTLY to the user's Telegram chat ID: {telegram_chat_id} Use the message tool: action=send, channel=telegram, target={telegram_chat_id} ``` ### Technical Analysis The function validates `sender_id` and `totp_code`, but it does not validate or encode `telegram_chat_id`. That value is interpolated multiple times into a natural-language task that is intended to be passed to `sessions_spawn`. Because the destination is represented as prompt text rather than trusted structured metadata, a value containing line breaks and additional instructions can alter the spawned agent's goals. The clean-room agent has access to decrypted vault entries and a messaging tool, making this an instruction-boundary violation with direct confidentiality consequences. This behavior exceeds minimu ...[truncated 1235 chars]- Remediation
View remediation
