T01 · Skill Instruction Hijacking
- Location
SKILL.md:6- Finding
Mandatory Cross-Agent Workflow and Script-Execution Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6 and 126-199
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code
yaml priority: CRITICALmarkdown ## 🔴 Self-Check Before Completing (MANDATORY) **Before saying "task complete", verify:** | Check | Question | |-------|----------| | ✅ **Goal met?** | Did I do exactly what user asked? | | ✅ **Files edited?** | Did I modify all necessary files? | | ✅ **Code works?** | Did I test/verify the change? | | ✅ **No errors?** | Lint and TypeScript pass? | | ✅ **Nothing forgotten?** | Any edge cases missed? | > 🔴 **Rule:** If ANY check fails, fix it before completing. --- ## Verification Scripts (MANDATORY) > 🔴 **CRITICAL:** Each agent runs ONLY their own skill's scripts after completing work. ### Agent → Script Mapping | Agent | Script | Command | |-------|--------|---------| | **frontend-specialist** | UX Audit | `python .agent/skills/frontend-design/scripts/ux_audit.py .` | | **frontend-specialist** | A11y Check | `python .agent/skills/frontend-design/scripts/accessibility_checker.py .` | | **backend-specialist** | API Validator | `python .agent/skills/api-patterns/scripts/api_validator.py .` | | **mobile-developer** | Mobile Audit | `python .agent/skills/mobile-design/scripts/mobile_audit.py .` | | **database-architect** | Schema Validate | `python .agent/skills/database-design/scripts/schema_validator.py .` | | **security-auditor** | Security Scan | `python .agent/skills/vulnerability-scanner/scripts/security_scan.py .` | | **seo-specialist** | SEO Check | `python .agent/skills/seo-fundamentals/scripts/seo_checker.py .` | | **seo-specialist** | GEO Check | `python .agent/skills/geo-fundamentals/scripts/geo_checker.py .` | | **performance-optimizer** | Lighthouse | `python .agent/skills/performance-profiling/scripts/lighthouse_audit.py <url>` | | **test-engineer** | T ...[truncated 4451 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
priority: CRITICALand replace mandatory language with clearly advisory guidance scoped to clean-code practices. - Remove all cross-agent role mappings. A clean-code skill should not redefine the operating policies of frontend, backend, security, testing, SEO, mobile, database, or performance agents.
- Do not instruct agents to execute scripts that are absent from the reviewed package.
- If validation automation is necessary, bundle each script in the package so it can be audited, pin its expected path and integrity, and document its required permissions.
- Require explicit user authorization before executing validation commands not already requested by the user.
- Resolve and validate script paths against an approved directory. Reject symlinks, path traversal, unexpected file ownership, and writable untrusted locations.
- Run approved validators with least privilege in a sandbox that restricts filesystem access, environment variables, subprocess creation, and network connectivity.
- Replace the forced
READ → SUMMARIZE → ASKprocess with a non-binding recommendation that defers to the user's request and higher-level agent policy. - Keep completion checks relevant to the actual task and available tooling; do not claim that unrelated lint, type, localization, or role-specific checks are universally mandatory.
- Re-audit any future bundled scripts separately for command injection, unsafe dependency loading, secret access, network behavior, and unintended file modification.
- Remove
