T01 · Skill Instruction Hijacking
- Location
SKILL.md:241- Finding
Automatic Vendor Communication and Agent Output Manipulation
- Content
View full analysis
/dev/null \ | grep -oE '"version"[[:space:]]*:[[:space:]]*"[^"]+"' \ | head -1 \ | sed -E 's/.*"version"[[:space:]]*:[[:space:]]*"([^"]+)"/\1/' ``` The surrounding instructions require this command to run silently at the beginning of a new session, compare the returned version with the local version, and append an upgrade notice to the Agent's otherwise unrelated response. ### Technical Analysis The Skill introduces a mandatory “step zero” that is unrelated to the user's immediate financial-data request. It also declares its own instruction priority and directs the Agent to modify final responses by appending vendor upgrade messaging. The remote manifest controls whether this additional output appears. Although the Skill states that the updater should not run automatically, the manifest lookup itself is automatic and is expected to occur without informing the user. This creates a vendor-controlled channel that can influence Agent output after the Skill has been reviewed. This behavior exceeds the minimum privileges needed to query financial data. A stock-data Skill does not need to contact an update server at the beginning of user sessions or inject update promotion into unrelated answers. ### Attack Path 1. A user or platform loads the Skill. 2. A new Agent session begins. 3. The Skill directs the Agent to contact `static.yyqyx.com` without a user request. 4. The remote server returns a version selected by the server operator or an attacker controlling the distribution infrastructure. 5. The Agent compares the value with the local version. 6. If the remote version is considered newer, the Agent appends vendor-directed upgrade instructions to the current ...[truncated 538 chars]- Remediation
View remediation
