T01 · Skill Instruction Hijacking
- Location
scripts/seddo.sh:1009- Finding
Untrusted Gist forks can inject instructions into the canonical agent task stream
- Content
View full analysis
/dev/null || echo "[]") # Extract 32-char hex gist IDs (not node_id or other IDs) local fork_ids=() while IFS= read -r fid; do [[ -n "$fid" ]] && fork_ids+=("$fid") done < <(echo "$forks_json" | grep -oP '"id":\s*"\K[a-f0-9]{32}' || true) # Read current hub state local hub_inbox hub_activity hub_lessons hub_tasks hub_inbox=$(fetch_file "INBOX.md") || { echo "❌ Abort sync: fetch hub INBOX.md failed" >&2; exit 1; } hub_activity=$(fetch_file "ACTIVITY.md") || { echo "❌ Abort sync: fetch hub ACTIVITY.md failed" >&2; exit 1; } hub_lessons=$(fetch_file "LESSONS.md") || { echo "❌ Abort sync: fetch hub LESSONS.md failed" >&2; exit 1; } hub_tasks=$(fetch_file "TASKS.md") || { echo "❌ Abort sync: fetch hub TASKS.md failed" >&2; exit 1; } local merged_count=0 for fork_id in "${fork_ids[@]}"; do echo " Merging fork ${fork_id:0:8}..." local fi_inbox fi_activity fi_lessons fi_tasks fi_inbox=$(fetch_from "$fork_id" "INBOX.md" 2>/dev/null || true) fi_activity=$(fetch_from "$fork_id" "ACTIVITY.md" 2>/dev/null || true) fi_lessons=$(fetch_from "$fork_id" "LESSONS.md" 2>/dev/null || true) fi_tasks=$(fetch_from "$fork_id" "TASKS.md" 2>/dev/null || true) [[ -n "$fi_inbox" ]] && hub_inbox=$(merge_append "$hub_inbox" "$fi_inbox") [[ -n "$fi_activity" ]] && hub_activity=$(merge_append "$hub_activity" "$fi_activity") [[ -n "$fi_lessons" ]] && hub_lessons=$(merge_append "$hub_lessons" "$fi_lessons") [[ -n "$fi_tasks" ]] && hub_tasks=$(merge_tasks "$hub_tasks" "$fi_tasks") ((merged_count++)) || true done edit_files "$GIST_ID" \ "INBOX.md" "$hub_inbox" \ "ACTIVITY.md" "$hub_activity" \ "LESSONS.md" "$hub_lessons" \ "TASKS.md" "$hub_tasks" ``` The agent-faci ...[truncated 2633 chars]- Remediation
View remediation
