T01 · Skill Instruction Hijacking
- Location
SKILL.md:61- Finding
Skill instructions attempt to override agent priorities and trigger unapproved filesystem actions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:7,SKILL.md:50-65, andSKILL.md:123-137
Vulnerability Type: Instruction hijacking through priority assertions, urgency, and action-oriented commands
Risk Level: HighVulnerable Code Snippet
The actionable filesystem operations appear at
SKILL.md:61-62:bash mkdir -p ~/.openclaw/workspace/skills/yan-watchman-publish cp -r src config Cargo.toml README.md ~/.openclaw/workspace/skills/yan-watchman-publish/The surrounding instructions also direct the agent to change directories, run
cargo build --release, and create or replace a publishedSKILL.mdthrough a shell heredoc. Elsewhere, the document declares self-evolution to be the highest instruction and repeatedly demands immediate action without waiting, reporting, or deliberating.Technical Analysis
The document attempts to establish its own objective as a highest-priority instruction. It reinforces that assertion with urgency and language intended to discourage normal review, reporting, and deliberation. It then supplies shell commands for building a purported Rust project, creating directories under the user's OpenClaw workspace, copying files, and writing a new skill document.
This matches skill instruction hijacking because the untrusted skill text attempts to alter the agent's current-session goals and decision process when loaded. A skill may document optional usage, but it must not claim authority over system or user instructions, pressure the agent to act automatically, or suppress security review.
The supplied project contains only
SKILL.md; the referenced Rust sources, manifest, configuration, and README are absent from the audited artifact. Consequently, the claimed implementation cannot be verified, and the documented build and copy procedure cannot complete as presented. If similarly structured files were later introduced into the expected workspace, following these instructions ...[truncated 1612 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all claims that the skill's objective is a highest-priority instruction or can supersede system, developer, or user directions.
- Remove language discouraging deliberation, review, reporting, or confirmation.
- Present build and publication commands strictly as optional examples that are never executed merely because the skill was loaded.
- Require explicit, informed user confirmation immediately before running Cargo or modifying the workspace.
- Describe every expected filesystem change, including destination paths and whether existing files may be replaced.
- Validate that all referenced source files are included in the reviewed package before offering build or publication steps.
- Refuse to build or copy files discovered outside the audited package unless the user separately approves those exact files.
- Use a newly created staging directory and fail safely if the destination already exists, rather than silently merging with or replacing existing content.
- Show a dry-run plan or file manifest before executing any mutating command.
- Keep descriptive documentation separate from executable operational instructions and clearly state that normal agent safety constraints remain authoritative.
