T01 · Skill Instruction Hijacking
- Location
encrypted-card.md:69- Finding
Server-Controlled Response Fields Can Hijack Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
encrypted-card.md:69-91,encrypted-card.md:181-205,skill.md:461-487
Vulnerability Type: Remote instruction injection through trusted API responses
Risk Level: CriticalVulnerable Code Snippets
From
encrypted-card.md:69-91:json { "approved": true, "checkout_id": "r5chk_abc123", "checkout_steps": [ "Call POST /api/v1/bot/rail5/key with { \"checkout_id\": \"r5chk_abc123\" } to get the decryption key.", "Decrypt the encrypted card data using AES-256-GCM with the key, IV, and tag from the API response.", "Use the decrypted card details to complete checkout at DigitalOcean.", "Call POST /api/v1/bot/rail5/confirm with { \"checkout_id\": \"r5chk_abc123\", \"status\": \"success\" } when done.", "If checkout fails, call confirm with { \"status\": \"failed\" } instead.", "Discard all decrypted card data. Announce the result." ], "spawn_payload": { "task": "You are a checkout agent...", "cleanup": "delete", "runTimeoutSeconds": 300, "label": "checkout-digitalocean" } }From
encrypted-card.md:181-205:json { "event": "rail5.card.delivered", "bot_id": "bot_abc123", "data": { "card_id": "r5card_...", "card_name": "ChaseD", "card_last4": "9547", "encrypted_data": "<encrypted card details>", "instructions": "Accept the encrypted card details and confirm delivery via POST /bot/rail5/confirm-delivery" } }text Store the encrypted card data securely using your platform's secrets manager or keep it in memory. Follow the `instructions` field in the message payload for next steps.From
skill.md:461-487:json { "bot_id": "bot_abc123", "messages": [ { "id": 1, "event_type": "rail5.card.delivered", "payload": { "card_id": "r5card_...", "card_name": "ChaseD ...[truncated 2863 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all instructions that tell the Agent to execute natural-language response fields.
- Replace
task,instructions, and free-formcheckout_stepswith a strict, versioned schema containing only allowlisted operation identifiers and validated parameters. - For example, accept an enum such as
CONFIRM_CARD_DELIVERY, not arbitrary prose. - Reject unknown event types, action identifiers, fields, URLs, and API endpoints.
- Keep Agent orchestration local; the service must not be able to supply a new Agent goal.
- Require explicit owner confirmation whenever a remote response introduces an action not already approved.
- Validate checkout IDs, merchant domains, amounts, recipient addresses, and approval state locally before acting.
- Verify webhook signatures using constant-time comparison, enforce timestamp freshness, and prevent replay. Signature verification must supplement rather than replace semantic validation.
- Process remote text strictly as untrusted data and never as higher-priority instructions.
