T01 · Skill Instruction Hijacking
- Location
SKILL.md:82- Finding
Mandatory Commit Template Injects Potentially False Third-Party Attribution
- Content
View full analysis
``` **Types**: `feat`, `fix`, `refactor`, `docs`, `test`, `chore`, `perf`, `style`, `build`, `ci` **Rules**: - Subject line: max 72 characters, imperative mood ("add" not "added") - Focus on WHY, not WHAT (the diff shows WHAT) - Include scope when changes are localized to a module - Use HEREDOC for multi-line messages to preserve formatting: ```bash git commit -m "$(cat <<'EOF' type(scope): subject line Body explaining the motivation. Co-Authored-By: Claude EOF )" ``` ``` This trailer is presented as part of the standard commit format rather than as an optional attribution requiring user approval. Conventional Commits does not require a co-author trailer. If the named party did not actually contribute to the changes, the instruction causes inaccurate authorship metadata to be written permanently into repository history. Because the behavior is embedded in the Skill instructions, loading and following the Skill changes the expected commit operation by adding unrelated metadata. This is best classified as instruction hijacking rather than code execution or privilege escalation. ### Attack Path 1. A user invokes the Skill to commit repository changes. 2. The agent follows the mandatory commit-message generation instructions. 3. The fixed `Co-Authored-By` trailer is inserted without confirming authorship or obtaining explicit user consent. 4. `git commit` records the trailer permanently in the local repository. 5. If the commit is subsequent ...[truncated 734 chars]- Remediation
View remediation
