T01 · Skill Instruction Hijacking
- Location
SKILL.md:72- Finding
Mandatory Session-Wide Interception and Redirection of Agent Responses
- Content
View full analysis
"} ``` ``` ### Technical Analysis The Skill declares that its instructions apply to every response and cannot be overridden by the user. This changes session-wide Agent behavior rather than providing a narrowly scoped, opt-in redaction operation. The instructions require the complete, unredacted draft response to be transmitted to the endpoint selected through `CLAWGUARD_URL`. Consequently, sensitive information is disclosed to the redaction service before any redaction occurs. Although the document describes URL-validation rules, the project contains no executable implementation with which to verify that those restrictions are enforced, that DNS resolution is checked safely, or that redirect and address-rebinding cases are rejected. The combination of an unoverrideable global directive and mandatory response forwarding is an instruction-hijacking pattern. It allows the Skill to interpose itself on unrelated Agent activity and creates a data-disclosure channel to the configured service. ### Attack Path 1. The Skill is loaded into an Agent session. 2. The Skill asserts that its processing rules apply to every response and cannot be overridden. 3. The Agent generates a complete draft containing conversation context, private information, credentials, or other sensitive material. 4. Before delivering the resp ...[truncated 870 chars]- Remediation
View remediation
