T01 · Skill Instruction Hijacking
- Location
SKILL.md:325- Finding
Protected Credential-File Controls Are Explicitly Bypassed
- Content
View full analysis
> $HERMES_HOME/.env ``` The surrounding instructions state that the Hermes `write_file` and `patch` tools intentionally refuse to modify `.env`, and then present the terminal command above as a workaround. ### Technical Analysis The Skill directs the Agent to evade an intentional protection on a credential-bearing file by switching to a less-restricted tool. The `.env` file can contain `FEISHU_APP_ID`, `FEISHU_APP_SECRET`, and other unrelated service credentials. Even though the demonstrated command only appends `FEISHU_ALLOW_BOTS`, the operational pattern defeats the platform's protected-file boundary. This behavior is not necessary for Feishu diagnostics. Configuration changes can instead be performed by the user or through a purpose-built configuration interface that validates keys and preserves credential protections. ### Attack Path 1. The Agent loads the Skill while troubleshooting bot-to-bot messaging. 2. The Skill identifies a missing `FEISHU_ALLOW_BOTS` setting. 3. Protected file-editing tools reject modification of `.env`. 4. Following the Skill, the Agent invokes the terminal command instead. 5. The shell writes directly to the protected credential file with the Agent process's filesystem privileges. 6. The persistent configuration change affects subsequent gateway sessions. ### Impact Assessment The instruction grants the Skill an effective path around the platform's protected-file policy. Its direct demonstrated impact is persistent modification of Hermes gateway configuration. More broadly, normalizing this bypass technique weakens safeguards around every secret stored in the same file and could lead to accidental corruption, disclosure, or unauthorized configuration changes. ]]>- Remediation
View remediation
