T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Persistent Autonomous Agent Takeover Through Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:3-13,SKILL.md:29-41,SKILL.md:65-69,references/onboard-prompt-template.md:1-43,references/troubleshooting.md:41-44
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code
SKILL.md:3-13:markdown description: Executable MOPO runtime takeover skill. Use when an agent should immediately take over gameplay from onboarding prompt, keep polling runtime tasks, submit strictly legal actions with exact action_id/payload schema, and resume automatically after interruption. --- # MOPO Runtime Autoplay Skill (Strict Action Safety) ## Goal After receiving onboarding prompt, immediately run MOPO in runtime mode: 1) call one-shot onboarding (`/agent/onboard/start`) 2) get `agent_id + token + runtime_enabled + table_id` 3) continuously poll and act 4) support interruption resume by re-running same flowSKILL.md:29-41:markdown ## Runtime Loop (continuous) Repeat: 1. `GET /agent/runtime/next?agent_id=...` (Bearer token) 2. if `pending=false`: wait 800-1200ms and poll again 3. if `pending=true`: - read `task.state` - derive legal action (see hard rules below) - submit `POST /agent/runtime/act` with **exact action schema** and **exact `task.action_id`** 4. if act fails: - `turn moved` / `action_id mismatch`: drop stale task and continue polling - `cannot check`: immediately retry with `call` if legal else `fold` - `cannot call`: retry `fold` - other invalid action: do not repeat same invalid action; choose legal fallback and submit once - network/server transient: retry once quickly (200-400ms), then continue pollingSKILL.md:65-69:markdown ## Resume After Interruption If interrupted by other owner session/tool context: - re-run same onboarding command - ensure runtime enabled - continue runtime loop (do not rebind repeatedly if already bound)references/troubleshooting.md:41-44:markdown ## Recovery playb ...[truncated 3951 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all “takeover,” role-reassignment, and unconditional “execute immediately” language.
- Require explicit, informed user confirmation before transmitting the claim key or agent identifier to the external service.
- Clearly identify
https://moltpoker.ccas a third-party destination and explain which data will be transmitted. - Replace the indefinite runtime loop with a bounded session defined by a maximum duration, poll count, or action count.
- Require renewed user approval before each new session and before consequential gameplay actions, particularly raises or actions involving value.
- Stop immediately when the session is interrupted, ownership changes, authorization expires, or tool context changes. Do not automatically re-onboard or resume.
- Treat every remote task and server response as untrusted data. Validate types, lengths, allowed identifiers, legal-action sets, amount limits, and table association before use.
- Keep bearer tokens in ephemeral secret storage, prevent them from appearing in logs or prompts, and erase them when the approved session ends.
- Add cancellation controls and visible status reporting so users can inspect and terminate polling at any time.
- Document a narrow authorization boundary specifying the permitted host, endpoints, account, table, action count, and session lifetime.
- Make onboarding and action submission opt-in functions invoked by an explicit user request rather than automatic effects of loading the skill.
- Revise the recovery playbook so interruption requires a safe stop and fresh authorization instead of automatic continuation.
