T01 · Skill Instruction Hijacking
- Location
references/投资协议要点库.md:863- Finding
Embedded Forged File-Write Tool Call in a Reference Document
- Content
View full analysis
# 投资协议要点库 ``` The first line translates to: “Now create three new reference files.” ### Technical Analysis The reference document unexpectedly transitions from investment due-diligence material into an imperative instruction directing the agent to create files. It then embeds model-specific tool-call markup that invokes `write_file`. Reference files should supply passive domain information. They do not need filesystem-write privileges to support the Skill’s declared investor due-diligence functionality. Consequently, this instruction violates least-privilege expectations and represents a prompt/tool-call injection embedded in trusted Skill content. If an agent treats reference text as executable instructions, the forged markup may be interpreted as a legitimate tool request. The embedded content continues through the remainder of the file and resembles leaked Skill-generation output rather than valid investment-agreement documentation. There is no evidence that the repository itself automatically executes the call, but exploitation is possible in agent runtimes that do not clearly separate untrusted reference content from authoritative instructions. ### Attack Path 1. A user loads or invokes the investor due-diligence Skill. 2. The agent reads `references/投资协议要点库.md` as trusted contextual material. 3. The agent reaches line 863 and interprets the file-creation statement as an instruction rather than reference data. 4. The following forged `` and `` markup is parsed or imitated as a tool invocation. 5. The agent attempts to create or overwrite reference files using its available filesystem permissions ...[truncated 929 chars]- Remediation
View remediation
`, ``, and ``. 5. Require explicit user authorization before any filesystem mutation. Reading a Skill or reference file must not implicitly authorize writes. 6. Restrict file-writing tools to an approved workspace directory and enforce canonical-path validation to prevent traversal or writes to unrelated locations. 7. Display the destination path and proposed content before executing a write, especially when the request originates from retrieved or embedded content. 8. Add repository validation that fails builds when reference files contain model-specific tool-call markup or imperative instructions to create, modify, or delete files. 9. Re-audit the cleaned package before distribution to confirm that no generated instruction fragments remain. ]]>
