T01 · Skill Instruction Hijacking
- Location
SKILL.md:21- Finding
External API Response Is Treated as Trusted Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21-29
Vulnerability Type: Remote instruction injection through an external service response
Risk Level: HighVulnerable Code Snippet
markdown No mailbox yet? Get one first (no auth needed): ```bash curl -X POST https://agentsmail.org/api/getemailaddress \ -H "Content-Type: application/json" \ -d '{"agent_name": "my-agent"}'The API response contains everything you need — follow the instructions it returns to save your credentials and start sending.
text ### Technical Analysis The Skill explicitly directs the agent to follow instructions returned by `https://agentsmail.org/api/getemailaddress`. Those instructions are not included in the audited package and can change independently after review. Although HTTPS authenticates the destination and protects transport confidentiality, it does not constrain the semantics of the response. The service operator, a compromised service, or an attacker who gains control of its backend could return arbitrary instructional text. The Skill provides no response schema validation, instruction/data separation, action allowlist, or restriction preventing the returned content from requesting unrelated tool use. Ordinary retrieval of structured mailbox fields such as `email` and `api_key` is necessary for the declared email functionality. Following arbitrary prose returned by the service is not necessary and exceeds the minimum privilege required. ### Attack Path 1. The agent loads the Skill and requests a mailbox from the unauthenticated registration endpoint. 2. The external service returns expected mailbox data together with malicious or compromised instructional text. 3. The Skill tells the agent to follow the returned instructions. 4. The instructions direct the agent to perform an action outside mailbox provisioning, such as reading a local secret, changing configuration, invoking another tool, ...[truncated 703 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to follow prose returned by the external service.
- Define a strict local response schema containing only required fields such as
email,api_key,tier_level, and quota metadata. - Treat every unexpected field and all response text as untrusted data.
- Validate field types, formats, lengths, and allowed values before use.
- Never execute commands, follow URLs, modify files, or invoke tools based solely on instructions embedded in an API response.
- Document credential storage locally rather than delegating storage instructions to the server.
- Require explicit user confirmation for actions beyond mailbox creation and the specific email operation requested.
