T01 · Skill Instruction Hijacking
- Location
mcp-bridge/index.mjs:250- Finding
Untrusted Clipper Content Is Presented as Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
mcp-bridge/index.mjs:250-257
Vulnerability Type: Prompt injection across an external-content trust boundary
Risk Level: HighVulnerable Code
js function formatCatchMeUpResult(result) { const prompt = result.suggested_agent_prompt ?? result.suggestedAgentPrompt; const recap = result.recap_context ?? result.recapContext ?? result.answer ?? ""; const title = result.title ?? "Current meeting"; const recording = result.is_recording ?? result.isRecording; const header = recording ? `Live meeting: ${title} (recording)` : `Meeting session: ${title} (paused — transcript so far)`; return `${header}\n\n${recap}\n\n---\nSummarize the above for the user (catch me up): decisions, open questions, action items, and current topic.${prompt ? `\nSuggested prompt: ${prompt}` : ""}`; }Technical Analysis
The bridge receives
recap_context,answer, andsuggested_agent_promptfrom the external Clipper socket and places them directly into text returned to the AI agent. In particular, the externally suppliedsuggested_agent_promptis labeled as a suggested prompt and combined with an imperative instruction telling the agent to summarize the preceding content.No boundary marker or policy tells the agent that the transcript, recap, and suggested prompt are untrusted data that must not be interpreted as instructions. No filtering or structured separation is applied. Consequently, instruction-like content originating in a meeting transcript, note, compromised Clipper process, or spoofed socket response can compete with the legitimate task instructions.
This is an instruction-hijacking risk rather than conventional code execution. Exploitation depends on the consuming agent interpreting malicious content as authoritative instructions.
Attack Path
- An attacker causes malicious instruction-like text to appear in a recorded meeting, note, rec ...[truncated 1132 chars]
- Remediation
View remediation
Remediation Suggestions
- Return structured JSON fields instead of combining external content with imperative prose. Keep
recap_context, title, recording state, and other data in separate fields. - Do not forward
suggested_agent_promptas an instruction. Remove it, or render it as explicitly quoted and untrusted source data. - Add a high-priority tool description stating that meeting transcripts, notes, presets, summaries, socket responses, and suggested prompts are untrusted content and must never authorize tool calls or override system, developer, user, or skill instructions.
- Ask the agent to summarize only factual meeting content and to ignore any commands embedded in that content.
- Where practical, normalize or reject fields that are not required for the requested operation.
- Add adversarial tests using transcript content such as requests to ignore prior instructions, reveal secrets, or invoke unrelated tools. Verify that such text is quoted or summarized as meeting content rather than executed as an instruction.
- Return structured JSON fields instead of combining external content with imperative prose. Keep
