T01 · Skill Instruction Hijacking
- Location
SKILL.md:22- Finding
Untrusted Remote Agent Cards Are Treated as Executable Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent markdown-only guide for agent contact cards, but it should be reviewed because it tells agents to trust remote card prose and try live webhook POSTs without enough consent or data-scope guardrails.
Install only if you are comfortable with agents fetching remote contact-card files and potentially contacting external endpoints. Before using it, treat fetched card text as untrusted, do not let it override your instructions, avoid sending personal or conversation data, and require a visible destination and payload confirmation before any webhook POST.
SKILL.md:22Untrusted Remote Agent Cards Are Treated as Executable Instructions
SKILL.md:154Live Demo Encourages Unreviewed Data Transmission to a Third-Party Webhook
The skill explicitly encourages testing against a live third-party webhook endpoint and then sending POST requests, but it provides no warning about sharing prompts, metadata, or other potentially sensitive user or agent information with an external service. In an agent environment, this can lead to unintended disclosure of private data, logging by the remote service, or triggering actions on infrastructure outside the user's control.
No suspicious patterns detected.