T01 · Skill Instruction Hijacking
- Location
SKILL.md:56- Finding
Explicit Bypass of the Host Safe-Delete Control
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 56
Vulnerability Type: Safety-control bypass through Skill instructions
Risk Level: MediumVulnerable setting:
text CODEBUDDY_SAFE_DELETE_ENABLED=0The surrounding instruction directs the agent to set this environment variable on a child process because the controlled environment's safe-delete hook would otherwise intercept deletion of intermediate streams.
Technical Analysis
The Skill explicitly instructs the agent to disable a host filesystem safety mechanism while running the download and DASH-stream merge workflow. This is not merely a missing safeguard: the documentation identifies the safe-delete hook as an obstacle and provides a setting intended to suppress it.
The environment variable is not scoped by the Skill to a verified list of temporary files. Consequently, every deletion performed by the affected child process may occur without the protection normally supplied by the host hook. The Skill text therefore crosses the trust boundary between untrusted Skill instructions and host-enforced safety constraints.
Although deleting intermediate DASH streams is part of the expected media-processing workflow, bypassing the platform control is broader than the legitimate need to clean up known workspace files.
Attack Path
- A user requests the Bilibili download and video-conversion workflow described by the Skill.
- The agent loads and follows the instructions in
SKILL.md. - During the download and stream-merging stage, the agent sets
CODEBUDDY_SAFE_DELETE_ENABLED=0for the child process. - The child process performs cleanup operations without safe-delete interception.
- Any deletion initiated within that process scope is no longer subject to the host protection, including deletion beyond the expected intermediate files if the invoked tool or its inputs cause a broader cleanup operation.
Impact Assessment
The byp ...[truncated 572 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to set
CODEBUDDY_SAFE_DELETE_ENABLED=0. - Keep the host safe-delete hook enabled for all child processes.
- Run downloads and media conversion inside a dedicated, path-restricted workspace.
- If intermediate files must be removed, delete only explicitly enumerated files beneath the workspace after canonicalizing and validating their paths.
- Require explicit user confirmation before any cleanup operation that affects files outside the dedicated temporary directory.
- Prefer a host-approved cleanup API or path-scoped exception rather than disabling the safety mechanism for an entire process.
- Verify that symbolic links and path traversal cannot redirect cleanup outside the workspace.
- Remove the instruction to set
