T01 · Skill Instruction Hijacking
- Location
SKILL.md:61- Finding
Untrusted External Learning Requests Can Override the Agent's Intended Plan
- Content
View full analysis
/learning/LEARNING-REQUESTS.md` if it exists. This file records learning requests from users, partners, or other agents. Priority rules: - Urgent requests override the original learning plan and must be studied immediately. - Near-term requests are inserted every three days. - Continue the original plan only when there are no external requests. Accept external request injection: users, partners, and other agents may add learning requests to LEARNING-REQUESTS.md, and urgent requests take priority over the original plan. ``` ### Technical Analysis The Skill treats entries in `LEARNING-REQUESTS.md` as trusted instructions rather than untrusted data. In particular, content classified as urgent is allowed to override the existing learning plan immediately. No authentication, provenance verification, authorization check, content validation, or user-confirmation boundary is defined for requests written by other agents. Consequently, any process or agent with write access to the file can influence the scheduled agent's goals. This is an instruction-hijacking weakness because attacker-controlled persistent file content can alter the agent's intended workflow when the Skill is loaded and executed. ### Attack Path 1. An attacker-controlled process or compromised agent obtains write access to `/learning/LEARNING-REQUESTS.md`. 2. It inserts a malicious request under the urgent section. 3. The scheduled daily-learning workflow reads the request file. 4. The Skill prioritizes the injected request over the original learning plan. 5. The agent performs attacker-selected research or other actions associated with the injected topic. 6. The res ...[truncated 556 chars]- Remediation
View remediation
