T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Untrusted Conversation Content Embedded as a Skill Instruction
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 9
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: MediumComplete Vulnerable Snippet:
markdown - Sender (untrusted metadata): ```json { "label": "openclaw-control-ui", "id": "openclaw-control-ui" } ``` [Wed 2026-05-06 17:48 EDT] Minor layout modifications: I like the stats card row, but for the listing I prefer a list view (datatable view) with pagination instead of a card list layoutTechnical Analysis
The skill stores untrusted sender metadata and a task-specific UI modification request directly within its authoritative
Workflowsection. The text explicitly identifies its source as untrusted, but it is nevertheless formatted as a workflow bullet that an agent may interpret as an instruction whenever the skill is loaded.This mixes untrusted transcript content with trusted skill instructions and creates a skill instruction-hijacking condition. An attacker able to influence content that is persisted into this file could substitute the benign layout request with instructions that alter the agent's current objective, request unrelated changes, or attempt to weaken operational safeguards.
Attack Path
- An attacker submits a crafted message through a source represented as sender metadata.
- The message is copied into
SKILL.mdunder the authoritativeWorkflowheading without validation or sanitization. - The skill persists as part of the project and is loaded during a later agent session.
- The agent interprets the persisted attacker-controlled text as workflow guidance.
- The agent may perform unrelated or unauthorized actions using whatever tools and permissions are already available in that session.
Impact Assessment
Exploitation can alter the agent's current task goals and resulting code or output. The affected scope includes sessions in which this skill is loaded and repositories or resources acces ...[truncated 397 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove line 9 from the skill because it contains task-specific, untrusted transcript content rather than reusable workflow guidance.
- Maintain a strict trust boundary between skill instructions and messages, sender metadata, logs, or conversation transcripts.
- If workflow learning is supported, allow only sanitized, task-agnostic rules through a structured schema and explicit human approval.
- Reject or quarantine candidate workflow entries containing sender fields, timestamps, quoted conversations, role markers, or imperative requests copied from user messages.
- Store provenance and trust labels separately from executable or authoritative instruction text.
- Review existing learned workflow files for similar persisted transcript content before loading them into agent sessions.
