T01 · Skill Instruction Hijacking
- Location
SKILL.md:139- Finding
Automatic Execution of Mutable Remote Heartbeat Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 139–144
Vulnerability Type: Remote instruction injection
Risk Level: HighVulnerable snippet:
markdown ## MusedIn (every 4 hours) If 4 hours since last MusedIn check: 1. Fetch https://musedin.com/heartbeat.md and follow it 2. Update lastMusedInCheck timestamp in memoryTechnical Analysis
The Skill establishes a recurring workflow that fetches mutable Markdown from
https://musedin.com/heartbeat.mdand directs the Agent to “follow it.” The downloaded document is therefore treated as instructions rather than untrusted network data.This creates an instruction channel that can change after the locally installed Skill has been reviewed. The remote service operator—or an attacker who compromises that service—could replace the currently benign heartbeat document with instructions that invoke tools or perform actions under the Agent’s authority. No pinned digest, signature verification, strict schema, instruction allowlist, or user-approval gate is specified before following updated content.
The bundled
HEARTBEAT.mdcontains ordinary MusedIn operations and explicitly treats messages from other users as content rather than instructions. Consequently, there is no evidence of a currently active malicious payload or malicious author intent. The issue is the reachable trust-boundary violation created by automatically following future remote prose.Attack Path
- The Skill is installed and its four-hour heartbeat workflow is enabled.
- The MusedIn service operator changes
heartbeat.md, or an attacker compromises the service or its publishing path. - The attacker places new Agent directives in the remote Markdown.
- After four hours, the Agent fetches the mutable document.
- Under the explicit “follow it” directive, the Agent interprets the network-controlled prose as operational instructions.
- The injected directives can request ...[truncated 811 chars]
- Remediation
View remediation
Remediation Suggestions
- Package the heartbeat procedure locally and treat it as immutable, version-reviewed Skill content.
- If remote updates are necessary, distribute them as a strictly defined data format rather than free-form Agent instructions.
- Verify remote updates using a pinned public key and authenticated signature, or pin an expected cryptographic digest.
- Require explicit user review and approval before activating any changed operational instructions.
- Enforce an allowlist of permitted heartbeat actions, endpoints, fields, and side effects.
- Treat all downloaded prose as untrusted content and prevent it from overriding system, developer, user, or local Skill instructions.
- Apply least-privilege tool restrictions to the recurring task and prohibit access to unrelated secrets, files, and services.
