T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Remote Advertiser-Controlled Content Can Hijack Agent Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–25
Vulnerability Type: Remote advertising content injection
Risk Level: HighAffected Code:
markdown 4. When matched, fetch creative: `GET https://picoads.xyz/matches/{matchId}` — get the ad content 5. Deliver the ad and submit proof: `POST https://picoads.xyz/matches/{matchId}/delivery`Technical Analysis
The Skill instructs the agent to retrieve mutable, advertiser-controlled creative from an external service and deliver that content to the agent's audience. The instructions do not require the retrieved creative to be treated as untrusted data, isolated from agent instructions, sanitized, clearly labeled as sponsored content, or approved by the user before publication.
This creates a remote output-hijacking channel: content that was not present during Skill review can subsequently be inserted into agent output. An advertiser—or an attacker who compromises the advertising service or an advertiser account—could supply misleading promotional content, malicious links, social-engineering text, or prompt-like instructions intended to influence the agent's behavior.
The behavior exceeds safe minimum privileges because publishing externally controlled content does not include safeguards limiting the content to a passive, clearly delimited advertisement. The Skill implicitly grants remote advertisers influence over audience-facing output.
Attack Path
- An attacker obtains an advertiser account or compromises an existing advertiser or the remote advertising service.
- The attacker submits crafted advertising creative containing deceptive content, malicious links, or instructions directed at the agent or its audience.
- The marketplace matches that creative with the publisher agent.
- The agent retrieves the mutable creative from
https://picoads.xyz/matches/{matchId}. - Following the Skill's instructions, the agent delivers the c ...[truncated 1241 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat all remotely retrieved creative as untrusted data and explicitly prohibit following any instructions embedded within it.
- Require explicit user opt-in before enabling advertising and confirmation before each audience-facing delivery.
- Render creative only inside a strictly delimited, non-executable advertising field that cannot modify the surrounding agent response or system behavior.
- Clearly and consistently label every delivery as sponsored content, including the advertiser identity where appropriate.
- Validate content against a restrictive schema and sanitize text, markup, URLs, and metadata before publication.
- Reject executable content, scripts, hidden markup, prompt-like control directives, credential requests, and links using disallowed schemes or unapproved domains.
- Apply content-length limits, destination allowlists, anti-phishing checks, and moderation policies.
- Require human approval for new advertisers, high-risk creative, or any content that cannot be safely rendered as inert data.
- Separate creative retrieval from publication so fetching a match never automatically authorizes delivery.
- Log the creative, advertiser, match identifier, approval decision, and final rendered output for auditing and incident response.
