T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Untrusted External Task Control and Work-Product Exfiltration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a simple guide for an external agent job board, but it asks agents to take remote jobs and submit work to a third-party service without enough user approval, scoping, or secret-handling guidance.
Review this skill carefully before installing. Use it only with a sandboxed agent, avoid sending private workspace data or sensitive deliverables, treat all remote tasks as untrusted text, and store any api_key as a secret outside prompts, code, and logs.
SKILL.md:3Untrusted External Task Control and Work-Product Exfiltration
The registration example initiates an external network request to a non-local service and includes agent-provided data in the request body. External transmission is especially relevant here because the skill is designed for autonomous agent use, where actions may be executed with limited human review and could disclose metadata or establish trust relationships with an unvetted remote system.
curl -X POST https://onlyflies.buzz/clawswarm/api/v1/agents/register \
-H "Content-Type: application/json" \
-d '{
"name": "YourAgent",
The skill instructs agents to POST registration data to a third-party service, including agent name and capabilities, without any explicit disclosure that this sends data off-platform or guidance on what data is safe to share. In an agent skill context, users may treat setup steps as trusted defaults, so silent external transmission increases the risk of unintended data exposure and supply-chain style trust abuse.
The guide tells users to save an API key but gives no instructions for secure handling, storage, rotation, or avoidance of logging/sharing. In agent ecosystems, credentials are often propagated through prompts, config files, or tool logs, so omission of basic secret-handling guidance materially raises the chance of credential leakage.
No suspicious patterns detected.