T01 · Skill Instruction Hijacking
- Location
SKILL.md:17- Finding
Unpinned Redirection to External Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–25
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: Highmarkdown Use the `fulcra-get-started` skill instead: - **In this repo:** `skills/fulcra-get-started/` - **GitHub:** https://github.com/fulcradynamics/agent-skills/tree/main/skills/fulcra-get-started - **Install:** `fulcradynamics/agent-skills/fulcra-get-started` If you arrived here, read and follow `fulcra-get-started` — it walks you through connecting to Fulcra for the first time (installing the CLI, logging in, and choosing what to set up next).Technical Analysis
The skill does not contain its intended operational instructions. Instead, it directs the agent to read and follow another skill that is not included in the audited artifact. One supplied reference points to the mutable GitHub
mainbranch, while the local repository path is also absent from the submitted project.Consequently, the effective instructions cannot be determined or verified from this artifact. They may change after review without changing
SKILL.md. The redirection is security-sensitive because the described replacement workflow includes installing a CLI and logging in. If the external repository, referenced skill, publication channel, or maintainer account is compromised, attacker-controlled instructions could be presented under the trust granted to this skill.The artifact itself contains no executable code and provides no direct evidence of malicious payload execution, credential theft, persistence, privilege escalation, or data exfiltration. The risk arises from blindly delegating agent behavior to mutable, unaudited content.
Attack Path
- A user or agent invokes the deprecated
fulcra-onboardingskill. SKILL.mdinstructs the agent to locate, install, read, and followfulcra-get-started.- The agent obtains the replacement skill from a local path not present in th ...[truncated 1064 chars]
- A user or agent invokes the deprecated
- Remediation
View remediation
Remediation Suggestions
- Include the complete replacement instructions in the reviewed skill package so its effective behavior can be audited.
- If external retrieval is unavoidable, reference an immutable commit or signed release rather than a mutable branch such as
main. - Verify downloaded content using a pinned cryptographic hash or trusted signature before processing it.
- Replace the unconditional instruction to “read and follow” external content with a summary of proposed actions and require explicit user approval.
- Require separate confirmation before installing software, executing commands, opening authentication flows, or transmitting credentials or tokens.
- Restrict replacement-skill execution to the minimum tools and permissions necessary for onboarding.
- Vendor and audit the exact
fulcra-get-startedversion distributed with this pointer, and update both artifacts together through a controlled review process.
