T01 · Skill Instruction Hijacking
- Location
SKILL.md:85- Finding
Spoofable Scheduled Callback Marker Bypasses the Normal Workflow
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:85-89andSKILL.md:609-610
Vulnerability Type: Unauthenticated event-source trust and workflow bypass
Risk Level: MediumVulnerable Skill Instructions
English rendering of the relevant instructions at
SKILL.md:85-89:text Step 0: Determine the trigger type before every skill invocation. Check whether the input contains the [DeepSOP-AutoQuery-Toby] marker: - If present: Treat it as a cron callback. Do not ask the user or wait for confirmation. Parse taskId, tobyDagTaskId, tobyCustomerPoolId, taskName, and feishuChatId from the input, skip Steps 1 through 4, and immediately execute Step 5. - If absent: Treat it as an active user request and continue with Step 1.The later restriction at
SKILL.md:609-610states:text Step 5 may execute only after receiving a systemEvent containing the [DeepSOP-AutoQuery-Toby] marker, or when the user explicitly asks for an early result query.Technical Analysis
The initial trigger logic authenticates a scheduled callback solely by checking whether attacker-controlled input contains a static text marker. It does not require or verify trusted event metadata, a cron job identifier, a nonce, a signature, or the event source.
Although the later instructions say that the marker must arrive in a
systemEvent, Step 0 does not enforce that condition and explicitly identifies the event through marker presence. An ordinary user can therefore reproduce the marker and provide arbitrary task identifiers.Once the marker is accepted, the agent is instructed to bypass the account-selection, prompt-confirmation, publication-parameter, and other normal workflow steps. It then performs authenticated result queries using the locally configured
DEEPSOP_API_KEY.Attack Path
- An attacker sends an ordinary user message containing
[DeepSOP-AutoQuery-Toby]. - The message supplies atta ...[truncated 1142 chars]
- An attacker sends an ordinary user message containing
- Remediation
View remediation
Remediation Suggestions
- Require trusted runtime metadata proving that the input is a
systemEvent; never infer event type from message text. - Bind each callback to a known cron job identifier recorded when the one-shot job is created.
- Include an unpredictable nonce in the scheduled payload and verify it before making authenticated requests.
- If the runtime supports signatures, sign the callback payload and verify the signature and timestamp.
- Reject
[DeepSOP-AutoQuery-Toby]when it appears in an ordinary user message. - Associate task identifiers with the current session when the task is submitted. Refuse result queries for identifiers not recorded in that session unless the user completes explicit authorization.
- Validate that
taskId,tobyDagTaskId, andtobyCustomerPoolIdhave the expected formats before constructing requests. - Make the Step 0 and Step 5 rules consistent by explicitly requiring verified event provenance in both locations.
- Require trusted runtime metadata proving that the input is a
