T01 · Skill Instruction Hijacking
- Location
SKILL.md:124- Finding
Automatic Retrieval and Execution of Mutable Remote Skill Instructions
- Content
View full analysis
# Full step-by-step guide for a skill ``` **If a skill matches** → `wonda skill get `, read it, adapt to context, execute each step. **If no skill matches** → build from scratch (Step 3). ``` ### Technical Analysis The Skill instructs the agent to retrieve additional instructions from an external service and execute each returned step. The retrieved content is not included in the audited package and can change independently after this version of `SKILL.md` has been reviewed. The instruction to “execute each step” establishes a dynamic instruction channel without: - Immutable version pinning - Content hashes or signature verification - A command allowlist - Validation against the original user request - A rule preventing remote instructions from changing safety constraints - Explicit user review and approval of the retrieved instructions Although the retrieved material is described as a content skill rather than executable software, it is consumed as authoritative agent instructions and may direct subsequent tool calls. A malicious or compromised remote skill could therefore alter the agent’s behavior without any modification to the locally audited package. ### Attack Path 1. An attacker compromises the Wonda skill service, a particular remote skill, or its publication account. 2. The attacker changes a remote skill so that it contains harmful or excessive instructions. 3. The agent follows the local requirement t ...[truncated 1053 chars]- Remediation
View remediation
