T01 · Skill Instruction Hijacking
- Location
SKILL.md:32- Finding
Unaudited Remote Instructions Expand the Skill Beyond Its Declared Scope
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32-39
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code:
markdown ## Setup (One Command) Tell your agent:set up skillboss.co/skill.md
text This auto-configures SkillBoss with 687 APIs — chat, image, video, audio, search, scraping, social data, email, and more.Technical Analysis
The skill instructs the agent to obtain and follow setup material hosted at
skillboss.co/skill.md. That external document is not included in the reviewed package, is not pinned to an immutable version or cryptographic digest, and can change independently after this skill has been audited.Consequently, the effective instructions executed during setup are not limited to the contents of the audited
SKILL.md. If the remote document is changed, compromised, or serves different content conditionally, it could introduce additional instructions that alter agent behavior or request further actions without those instructions appearing in this package.The setup also explicitly expands access from the declared Whisper speech-to-text functionality to 687 APIs, including scraping, social-data, and email services. This exceeds the minimum capabilities needed to submit audio for transcription and violates least-privilege principles.
The separate API examples transmit an authorization bearer token and user-provided content to
https://api.skillboss.co/v1/run. This transmission is disclosed and is functionally expected for the brokered transcription service; the reviewed file does not show the credential being sent to an unrelated destination. Nevertheless, users should be clearly informed that their content is processed by SkillBoss rather than sent directly to OpenAI.Attack Path
- A user or agent loads the locally audited Whisper skill.
- The agent follows the setup instruction to access
skillboss.co/skill.md.
...[truncated 1303 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction that asks the agent to set up the skill from a mutable external Markdown document.
- Include all required setup instructions directly in the reviewed package.
- Restrict configuration and documented permissions to the single Whisper transcription endpoint required by the skill.
- If remote setup material is unavoidable, reference an immutable version and verify it against a cryptographic hash or authenticated signature before use.
- Display the retrieved instructions to the user and require explicit confirmation before applying configuration or enabling additional APIs.
- Use an API key scoped only to
openai/whisper-1and deny unrelated services server-side. - Clearly disclose that authentication credentials and transcription content are sent to SkillBoss as an intermediary, including applicable retention and privacy policies.
- Replace the broad “687 APIs” setup flow with a minimal, auditable procedure that configures only the endpoint, credential, and permissions necessary for speech-to-text.
