T01 · Skill Instruction Hijacking
- Location
SKILL.md:21- Finding
Untrusted Project Plan Content Is Repeatedly Injected into the Agent Context
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:21-25,SKILL.md:89-95, andtemplates/task_plan.md:126-130
Vulnerability Type: Indirect instruction hijacking through persistent, project-controlled planning files
Risk Level: MediumVulnerable Code
SKILL.md:21-25:yaml PreToolUse: - matcher: "Write|Edit|Bash" hooks: - type: command command: "cat task_plan.md 2>/dev/null | head -30 || true"SKILL.md:89-95:markdown ### 2. The 2-Action Rule > "After every 2 view/browser/search operations, IMMEDIATELY save key findings to text files." This prevents visual/multimodal information from being lost. ### 3. Read Before Decide Before major decisions, read the plan file. This keeps goals in your attention window.templates/task_plan.md:126-130:markdown ## Notes <!-- REMINDERS: - Update phase status as you progress: pending → in_progress → complete - Re-read this plan before major decisions (attention manipulation) - Log ALL errors - they help avoid repetitionTechnical Analysis
The
PreToolUsehook readstask_plan.mdfrom the current working directory and inserts its first 30 lines into the context before every Write, Edit, or Bash operation. The file is located in the active project rather than in a trusted, Skill-controlled state directory.Consequently, a repository author, previous process, or indirect prompt-injection source can control the text printed by this hook. No ownership, provenance, integrity, or content validation is performed before the file is read. The content is also not clearly delimited as untrusted data that must never be interpreted as Agent instructions.
The surrounding Skill instructions amplify this trust-boundary failure by directing the Agent to reread the plan before decisions and persist discoveries in planning files. This creates two related risks:
- **Current-session instructio ...[truncated 2643 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic context injection from project-controlled files. Do not print
task_plan.mdautomatically before sensitive tool calls. - Store trusted Agent state separately. Place planning state in a dedicated Skill or application state directory outside the target repository, with restrictive permissions and verified ownership.
- Treat project files as untrusted data. If a project plan must be loaded, surround it with explicit boundaries and instructions stating that its contents are data only and must not override user, system, or Skill policies.
- Validate provenance and integrity. Record whether the Skill created the file, reject symbolic links and unexpected owners where applicable, and use an integrity marker or structured schema rather than unrestricted Markdown instructions.
- Use structured fields. Parse only expected data such as phase names and status values instead of inserting arbitrary file contents into Agent context.
- Require approval for consequential actions. Any Bash command, external request, sensitive-file access, or out-of-scope modification derived from planning content should require explicit user confirmation.
- Prevent persistent instruction storage. Sanitize findings imported from web pages, repositories, documents, or tool output before writing them to persistent planning files. Never preserve imperative instructions from untrusted sources as Agent rules.
- Limit scope and lifecycle. Bind planning state to a specific task, expire or archive it at completion, and do not automatically reuse existing plans across unrelated sessions.
- Fail safely. If the plan is absent, malformed, untrusted, or unexpectedly modified, continue without injecting it rather than silently accepting arbitrary content.
- Remove automatic context injection from project-controlled files. Do not print
