YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]
High
- Category
- YARA Match
- Content
--- name: zero-trust-protocol version: 1.0.0 description: Zero-trust security framework for AI agents. Verification flow for all external actions, URL interactions, installations, and credential handling. Prevents prompt injection, phishing, and malicious package execution. STOP-THINK-VERIFY-ASK-ACT-LOG. homepage: https://clawhub.com changelog: Initial release - Verification flow, installation rules, credential handling, URL safety, red flag detection, external action classification metadata: openclaw: emoji: "🔒" requires: bins: [] os: - linux - darwin - win32 --- # Zero Trust Security Protocol Security-first behavioral guidelines for AI age- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
