T01 · Skill Instruction Hijacking
- Location
SKILL.md:14- Finding
Global Agent Behavior and Tool-Routing Override
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-17 and 71-77
Vulnerability Type: Global instruction and execution-path override
Risk Level: HighVulnerable Snippet:
markdown # DashClaw Governance Protocol You are an agent governed by DashClaw. DashClaw provides the governance tools (via MCP) and this skill teaches you how to use them correctly. Follow this protocol for every action you take.markdown ### External API Calls Never make direct HTTP calls to external APIs that are registered as DashClaw capabilities. Always use `dashclaw_invoke` — it runs the full governance loop automatically: guard check, execution, outcome recording. Before invoking an unknown capability ID, call `dashclaw_capabilities_list` to verify it exists and check its health status.Technical Analysis
The skill declares that the agent is governed by DashClaw and applies its protocol to every action rather than limiting the instructions to an explicitly requested DashClaw operation. It also replaces ordinary external API execution paths with
dashclaw_invoke.This is an instruction-level control-flow override. When the skill is loaded, it changes how the agent selects tools, decides whether operations may proceed, and routes external API activity. Although this behavior is consistent with the skill's stated governance purpose, it creates a broad trust boundary in which DashClaw can mediate unrelated agent actions.
Attack Path
- The agent loads the skill.
- The global instruction to follow the protocol for every action becomes active.
- The agent identifies an external API as a registered DashClaw capability.
- The skill prevents use of the normal direct execution path.
- The agent submits the operation through
dashclaw_invoke. - DashClaw mediates execution and records the operation, potentially blocking, modifying, or observing it according to externally supplied co ...[truncated 448 chars]
- Remediation
View remediation
Remediation Suggestions
- Scope the protocol to tasks for which the user explicitly requests DashClaw governance.
- Replace “every action you take” with narrowly defined action types and trust boundaries.
- State explicitly that system, developer, safety, and current user instructions take precedence.
- Require informed user approval before redirecting an operation from its normal tool to a DashClaw capability.
- Display the capability ID, destination system, transmitted fields, and expected side effects before invocation.
- Permit a safe refusal path when DashClaw is unavailable instead of silently changing execution semantics.
- Enforce an allowlist of capability IDs and parameter schemas at the client boundary.
