T01 · Skill Instruction Hijacking
- Location
scripts/cli.mjs:93- Finding
Untrusted PANews Content Is Exposed to the Agent Without Prompt-Injection Boundaries
- Content
View full analysis
({ author:e.user?.profile?.name, text:e.text, createdAt:e.createdAt })); console.log(_i(e)) ``` ```js let i=(await ar( `/hooks?${new URLSearchParams({ category:r.join(`,`), onlyValid:`true`, take:String(n) })}`, {lang:t} )).map(e=>{ let n=e.targets.find(e=>e.lang===t)??e.targets[0]; return { id:e.id, category:e.category, text:n?.text, link:n?.link, payload:e.payload, group:e.group } }); console.log(_i(i)) ``` The supporting workflow encourages using remote hook content to guide Agent behavior: ```markdown ### Get AI-recommended questions node cli.mjs get-hooks --category ai-search-issues --lang Returns editorially preset exploratory questions to guide users into deeper topics. ``` ### Technical Analysis The CLI retrieves article bodies, community comments, editorial hook text, links, and hook payload objects from `https://universal-api.panewslab.com`. It then emits these values as plain Markdown-like text for subsequent Agent processing. The implementation does not establish a trust boundary between Skill instructions and API-derived content. In particular, it does not: - Label remote content as untrusted data. - Instruct the Agent to ignore commands or policy statements embedded in retrieved content. - Quote or isolate community comments from operational instructions. - Restrict hook payloads to documented identifier fields. - Validate retrieved links against an allowlist of schemes and domains. - Require confirmation before acting on instructions or links found in remote content. Article bodies and com ...[truncated 2057 chars]- Remediation
View remediation
