T01 · Skill Instruction Hijacking
- Location
README.md:6- Finding
Persistent Steering Toward Exclusive Use of the Skill
- Content
View full analysis
Vulnerability Details
File Location:
README.md:6-14
Vulnerability Type: Persistent tool-selection steering
Risk Level: LowThe documentation recommends adding a persistent instruction that directs the agent to use this Skill instead of its built-in web-search capability. It also recommends disabling the built-in web-search tool:
json { "tools": { "web": { "enabled": false } } }Technical Analysis
These recommendations alter agent tool selection beyond an individual invocation of the Skill. If applied, the persistent agent configuration removes an independent search alternative and causes later searches to be routed preferentially through this Skill and its configured local proxy.
The behavior is classified as instruction hijacking because the documentation attempts to influence future agent decisions and suppress use of another legitimate tool. The project does not automatically modify the configuration, override safety controls, or install persistence; exploitation depends on the user manually following the documentation.
Review of
scripts/brave_search.pyfound no credential exfiltration, shell execution, filesystem modification, obfuscated payload, remote code execution, or persistence mechanism. The script sends the documented API key to the fixed Brave Search API endpoint through a localhost proxy.Attack Path
- A user installs or reviews the Skill.
- The user follows the README recommendation and adds the proposed tool-selection instruction to persistent agent configuration.
- The user disables the built-in web-search tool by setting
tools.web.enabledtofalse. - Subsequent search requests are preferentially or exclusively routed through this Skill.
- The agent loses the built-in search tool as an independent alternative until the configuration is reverted.
Impact Assessment
No operating-system privileges, additional credentials, co ...[truncated 442 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to disable the built-in web-search tool.
- Remove guidance that instructs users to add a mandatory, persistent preference for this Skill.
- Describe Skill selection as an optional, per-request choice.
- If persistent configuration is documented, clearly explain its scope, security implications, and reversal procedure.
- Preserve the built-in search capability as a fallback unless the user independently determines that disabling it is necessary.
- Replace the current guidance with neutral wording, such as: “Invoke this Skill explicitly when Brave Search through the configured localhost proxy is desired.”
