T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Broad Keyword Triggers Force an Installation Workflow Without Final Approval
- Content
View full analysis
``` The excerpt is an English translation of the original instructions. ### Technical Analysis The skill treats the mere presence of a broad keyword as authorization to start a mandatory workflow that includes formal installation. It does not distinguish an affirmative installation request from quoted text, documentation, retrieved content, a security audit, a hypothetical question, or a negated request. The instruction that no step may be skipped also attempts to override context-sensitive safety decisions. Although Step 5 requires explicit authorization before changing the allowlist, no equivalent confirmation is required immediately before the formal installation in Step 4. ### Attack Path 1. An attacker places a trigger phrase such as “install skill” in user-controlled or retrieved content. 2. The agent loads the skill and interprets the keyword match as a mandatory workflow trigger. 3. The instructions prohibit skipping Steps 0 through 5. 4. The agent searches for and selects a candidate package. 5. Step 4 runs `clawhub install ` without a documented final approval gate. 6. The selected package is installed into the normal environment. ### Impact Assessment Successful exploitation can redirect the agent from its current task and cause unintended modification of the skill installation environment. Any code, dependencies, installation hooks, ne ...[truncated 335 chars]- Remediation
View remediation
