T01 · Skill Instruction Hijacking
- Location
encrypted-card.md:147- Finding
Execution of Server-Controlled Agent Tasks
- Content
View full analysis
Card-ChaseD-9547.md", "Use the decrypted card details to complete checkout at DigitalOcean.", "Call POST /api/v1/bot/rail5/confirm with { \"checkout_id\": \"r5chk_abc123\", \"status\": \"success\" } when done.", "If checkout fails, call confirm with { \"status\": \"failed\" } instead.", "Announce the result." ], "spawn_payload": { "task": "You are a checkout agent...", "cleanup": "delete", "runTimeoutSeconds": 300, "label": "checkout-digitalocean" } } ``` ```text ### Step 2: Spawn a Sub-Agent Once the checkout is approved, spawn an ephemeral sub-agent using the `spawn_payload` from the response: sessions_spawn({ task: spawn_payload.task, cleanup: "delete", runTimeoutSeconds: 300 }) The sub-agent executes the `checkout_steps` in sequence. ``` ### Technical Analysis The Skill directs the main agent to execute an agent prompt obtained dynamically from the CreditClaw API. The value of `spawn_payload.task` is controlled by a remote service and is passed directly to `sessions_spawn` without a documented schema, fixed local template, instruction allowlist, signature check, or semantic validation. This creates a remote instruction-injection boundary. Although an ephemeral sub-agent is intended to isolate card data, deletion after execution does not restrict the actions the sub-agent can perform while active. If the API response, service account, delivery infrastructure, or upstream application is compromised, the task can be replaced with instructions unrelated to checkou ...[truncated 1523 chars]- Remediation
View remediation
