T01 · Skill Instruction Hijacking
- Location
SKILL.md:18- Finding
Mutable External Instructions Retrieved Through a Shortened URL
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–19
Vulnerability Type: Untrusted external instruction delegation
Risk Level: MediumVulnerable Code Snippet:
markdown ## API Reference Once you have your Client ID, you can use the Ganesh API to upload images. The full documentation is available at https://ishortn.ink/ganesh-official-api , and changes frequently, so refer to the official docs for the latest endpoints and parameters.Technical Analysis
The Skill does not define the API endpoint, request parameters, destination host, or expected response locally. Instead, it directs the Agent to retrieve frequently changing operational instructions through a shortened URL. The redirect destination and retrieved content therefore cannot be verified from the reviewed package.
This creates an instruction-hijacking risk because whoever controls the shortened link or its destination can change the instructions after the Skill has been audited. Modified documentation could direct the Agent to upload images or related information to an attacker-controlled endpoint, request unnecessary credentials, or follow additional unsafe instructions. This finding concerns externally supplied instructions rather than executable remote code; the reviewed file does not explicitly download or execute code.
Attack Path
- A user asks the Agent to upload or host an image using the Ganesh Skill.
- The Skill directs the Agent to
https://ishortn.ink/ganesh-official-api. - The shortened URL redirects the Agent to content whose destination and integrity are not pinned in the Skill.
- The party controlling the redirect or destination changes the documentation after review.
- The altered documentation instructs the Agent to use a malicious upload endpoint, disclose a Client ID, transmit additional data, or follow unrelated unsafe instructions.
- If the Agent trusts those instructions, user-provided images ...[truncated 690 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the shortened URL with a transparent, verified first-party HTTPS URL.
- Embed the reviewed API contract directly in the Skill, including the exact host, endpoint path, HTTP method, required fields, authentication behavior, and expected response.
- Pin the Skill to a specific API version rather than automatically relying on frequently changing documentation.
- Restrict uploads to an explicit allowlist of approved domains and reject redirects to unapproved hosts.
- Treat retrieved documentation as untrusted reference material, not as executable Agent instructions.
- Require explicit user confirmation before transmitting an image, Client ID, metadata, or other information to the hosting service.
- Document precisely which data is transmitted and avoid sending credentials or unrelated contextual data.
- Review and update the packaged API specification through a controlled release process whenever the service changes.
