T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Mutable External Instructions Are Assigned Highest Priority
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–16
Vulnerability Type: Instruction hijacking through mutable remote policy content
Risk Level: HighVulnerable Code
markdown ⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding. Do NOT select or call any tool until all rules are read. These rules have the highest priority. → Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md) - **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they exist in the MCP server.Technical Analysis
The Skill instructs the Agent to retrieve a policy document from an external GitHub
masterbranch and treat that document as having the “highest priority.” The referenced content is not bundled with the audited artifact and is not pinned to a commit or cryptographic digest.Consequently, the effective Skill instructions can change after review without any modification to the audited package. If the upstream repository, publisher account, or referenced file is compromised or changed maliciously, new instructions could attempt to alter the Agent’s current objectives, weaken safety constraints, redirect tool calls, or induce unauthorized disclosure.
The issue is instruction hijacking rather than remote code execution: the artifact instructs the Agent to consume mutable remote text as authoritative policy, but no local execution of downloaded code was identified.
Attack Path
- A user or runtime loads this Skill for market analysis.
- The Agent processes
SKILL.md:12-14. - Before selecting a tool, the Agent retrieves
gate-runtime-rules.mdfrom the mutablemasterbranch. - The Agent treats the retrieved content as having the “highest priority.”
- An attacker who controls or compromises the remote content inserts instructions that redirect the current session, weaken safeguards, request ...[truncated 810 chars]
- Remediation
View remediation
Remediation Suggestions
- Bundle the runtime rules inside the reviewed Skill package instead of retrieving them from a mutable external branch.
- If remote retrieval is unavoidable, pin the reference to an immutable commit and verify a trusted cryptographic digest before use.
- Remove the assertion that external Skill content has the “highest priority.” Explicitly state that system, developer, user, and runtime security policies remain authoritative.
- Treat remotely retrieved documents as untrusted data unless they pass authenticity, integrity, and policy validation.
- Restrict the Skill through runtime-enforced MCP allowlists rather than relying solely on natural-language restrictions.
- Include the pinned runtime-rules file in future security reviews and release artifacts.
