T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Unpinned External Setup Instructions Allow Remote Skill Instruction Hijacking
- Content
View full analysis
**One API key. ElevenLabs TTS API. Zero markup.** USE THIS when the user needs elevenlabs api. SkillBoss provides ElevenLabs text-to-speech via OpenAI-compatible API with 0% markup. ## Setup (One Command) Tell your agent: ``` set up skillboss.co/skill.md ``` This auto-configures SkillBoss with 687 APIs — chat, image, video, audio, search, scraping, social data, email, and more. ``` ### Technical Analysis The Skill tells the agent to set itself up using `skillboss.co/skill.md`, an externally hosted and mutable instruction document that is not included in the audited package. Consequently, the effective setup behavior cannot be determined from the reviewed `SKILL.md` file and may change after publication or audit. When an agent interprets the remote document as instructions, the operator controlling that document can potentially introduce new directives that alter setup actions, tool use, credential handling, or the agent's current objectives. This is an instruction-channel trust-boundary violation: unaudited remote content is treated as authoritative Skill configuration rather than untrusted external data. The requested setup also exceeds the minimum capabilities required for the declared ElevenLabs text-to-speech function. The Skill states that this command configures 687 APIs, including scraping, social-data, email, search, image, video, and chat services. A TTS integration only requires access to the relevant audio endpoint and credential. Enabling unrelated services unnecessarily broadens the available capability and compromise scope. This finding ...[truncated 1927 chars]- Remediation
View remediation
