T01 · Skill Instruction Hijacking
- Location
SKILL.md:15- Finding
Installation Delegates Agent Control to Mutable Remote Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This media-generation skill is mostly coherent, but it needs Review because installation delegates control to mutable remote instructions and credentialed requests use an unvalidated configurable endpoint.
Install only if you are comfortable with prompts and reference images being sent to Nova Video. Do not use sensitive, private, or proprietary media without consent, avoid following mutable remote SKILL.md instructions as an install method, and ensure NOVA_BASE_URL points only to the intended HTTPS Nova endpoint before using your API key.
SKILL.md:15Installation Delegates Agent Control to Mutable Remote Instructions
SKILL.md:38Bearer API Credential Can Be Sent to an Unvalidated Configurable Endpoint
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
imageUrl from the responsecurl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
VIDEO_RESP=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
"Generate a cyberpunk-style cityscape at night"
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt": "Cyberpunk cityscape at night, neon reflections on rain-soaked streets, cinematic quality", "size": "2k"}'
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo "Reference image: $IMAGE_URL"
# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
ATTEMPT=0
while [ $ATTEMPT -lt $MAX_ATTEMPTS ]; do
ATTEMPT=$((ATTEMPT + 1))
STATUS=$(curl -s "$NOVA_BASE_URL/api/openapi/video?taskId=$TASK_ID" \
-H "Authorization: Bearer $NOVA_API_KEY")
STATE=$(echo $STATUS | python3 -c "import sys,json; print(json.load(sys.stdin)['data']['status'])")
echo "[$ATTEMPT/$MAX_ATTEMPTS] Status: $STATE"
The trigger phrases are broad enough that the skill may activate on loosely related requests, causing users' prompts or referenced URLs to be sent to an external service without clear intent. In an agent ecosystem, overbroad activation increases the chance of unintended third-party data disclosure and surprising tool behavior.
The skill markets simple image/video generation but does not prominently warn that user prompts and referenced image URLs are transmitted to an external API endpoint. This can lead to inadvertent disclosure of sensitive prompts, proprietary media URLs, or personal data to a third party without informed consent.
This workflow transmits the user's free-form prompt to an external API using an authorization-bearing request. That is expected for the skill's function, but it is still a real data-transfer risk because prompts may contain sensitive or proprietary information and the skill does not require explicit per-request consent.
imageUrl from the responsecurl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The video submission step sends a derived motion prompt and reference image URL or base64 image to a third-party API. This expands the exposure surface beyond text prompts to potentially sensitive media content, making unintended disclosure more consequential.
VIDEO_RESP=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
A default locale of zh without user opt-in can cause unintended data handling or content generation behavior inconsistent with the user's expectations. While not a direct exploit vector, silent defaults that alter external processing can create privacy, compliance, or output-integrity concerns.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"Generate a cyberpunk-style cityscape at night"
curl -s -X POST "$NOVA_BASE_URL/api/openapi/image" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt": "Cyberpunk cityscape at night, neon reflections on rain-soaked streets, cinematic quality", "size": "2k"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "Reference image: $IMAGE_URL"
# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo "Reference image: $IMAGE_URL"
# Step 2: Submit video task with motion prompt
TASK=$(curl -s -X POST "$NOVA_BASE_URL/api/openapi/video" \
-H "Authorization: Bearer $NOVA_API_KEY" \
-H "Content-Type: application/json" \
-d "{\"prompt\": \"Slow aerial drone flyover, golden sunrise light filtering through treetops, morning mist drifting through valleys, gentle camera push forward, cinematic\", \"imageUrl\": \"$IMAGE_URL\", \"duration\": 4, \"aspectRatio\": \"16:9\", \"resolution\": \"720p\"}")
The manifest describes a media-generation skill for creating images/videos and checking or listing generations, but this section adds filesystem write behavior by instructing the agent to save the full video URL into video_url.txt. Writing local files is not mentioned in the stated skill purpose and goes beyond the described user-facing operations.
No suspicious patterns detected.