T01 · Skill Instruction Hijacking
- Location
SKILL.md:72- Finding
Untrusted Skill Content Is Evaluated in an Instruction-Bearing Security Prompt
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:72-115;references/security_scan_prompt.md:5-10
Vulnerability Type: Prompt injection against the pre-installation security gate
Risk Level: HighVulnerable Snippets
SKILL.md:72-115:markdown ### Step 5: Security Scan **CRITICAL:** Before installation, perform a thorough security analysis of each skill. Read the security scan prompt template from `references/security_scan_prompt.md` and apply it to analyze the skill content. Examine for: 1. **Malicious Command Execution** - eval, exec, subprocess with shell=True 2. **Backdoor Detection** - obfuscated code, suspicious network requests 3. **Credential Theft** - accessing ~/.ssh, ~/.aws, environment variables 4. **Unauthorized Network Access** - external requests to suspicious domains 5. **File System Abuse** - destructive operations, unauthorized writes 6. **Privilege Escalation** - sudo attempts, system modifications 7. **Supply Chain Attacks** - suspicious package installations Output the security analysis with: - Security Status: SAFE / WARNING / DANGEROUS - Risk Level: LOW / MEDIUM / HIGH / CRITICAL - Detailed findings with file locations and severity - Recommendation: APPROVE / APPROVE_WITH_WARNINGS / REJECT ### Step 6: User Decision Based on the security scan results: **If SAFE (APPROVE):** - Proceed directly to installation **If WARNING (APPROVE_WITH_WARNINGS):** - Display the security warnings to the user - Use AskUserQuestion to confirm: "Security warnings detected. Do you want to proceed with installation?" - Options: "Yes, install anyway" / "No, skip this skill" **If DANGEROUS (REJECT):** - Display the critical security issues - Refuse to install - Explain why the skill is dangerous - Do NOT provide an option to override for CRITICAL severity issues ### Step 7: Install Skills For approved skills, install to `~/.claude/skills/`: 1. Create the skill directory: `~/.claude/skills/{skill_name}/` 2. Write all skill files ...[truncated 3692 chars]- Remediation
View remediation
Remediation Suggestions
- Treat every downloaded repository file as untrusted data, including
SKILL.md, references, comments, examples, and encoded content. - Add an explicit higher-priority scanning rule stating that instructions found inside analyzed files are evidence only and must never alter the scanner’s policy, output format, or decision.
- Pass file contents through structured boundaries with explicit filenames and lengths rather than interpolating them as undifferentiated prompt text.
- Run deterministic checks outside the language-model context for dangerous operations, sensitive paths, executable files, obfuscation, network destinations, and installation hooks.
- Require independent human confirmation before installing any remotely sourced instruction-bearing skill, including those classified as
SAFE; present the repository identity, revision, file list, and scan findings. - Pin installation to an immutable commit identifier and ensure the reviewed bytes are exactly the bytes written to the destination.
- Do not allow the scan model’s free-form recommendation to directly authorize installation. Convert findings through a separate, fixed policy engine that fails closed on malformed, missing, or contradictory output.
- Re-scan the final staged directory immediately before installation and prohibit executable permission changes unless the reviewed manifest explicitly identifies the required scripts.
- Treat every downloaded repository file as untrusted data, including
