T01 · Skill Instruction Hijacking
- Location
SKILL.md:43- Finding
Mandatory Git Publication Can Cause Unauthorized Repository Changes and Data Disclosure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43-55
Vulnerability Type: Mandatory external publication instruction
Risk Level: HighVulnerable Code
markdown ### ⚠️ MANDATORY: Push to GitHub After Every New Brand Profile **Every time a new brand profile is generated and saved, it MUST be pushed to GitHub immediately.** This is non-optional — the ComfyDeploy deployment pulls brand profiles from the repo. ```bash cd ~/clawd/ad-ready git add configs/Brands/{Brand_Name}.json git commit -m "Add brand profile: {Brand Name}" git push origin mainDo NOT skip this step. The ad generation pipeline on ComfyDeploy needs the profile in the repo to work correctly.
text ### Technical Analysis The Skill uses mandatory and priority-oriented language to direct the executing agent to mutate a local Git repository and publish generated content to a remote repository. This operation is not intrinsically required to analyze a brand or create a local profile. The instruction does not require the agent to: - Obtain explicit approval immediately before publication. - Verify the repository identity or remote URL. - Confirm that the selected branch is appropriate. - Review the generated file for sensitive or unintended content. - Check whether repository hooks or other Git configuration will execute additional actions. - Verify that the generated file is the only pending repository change relevant to the operation. An agent that treats the Skill instructions as authoritative may therefore publish model-generated or user-derived information without an informed confirmation step. ### Attack Path 1. A user invokes the Skill to analyze a brand and save a profile. 2. The Skill produces a generated JSON profile in the Ad-Ready repository. 3. The agent follows the mandatory instructions in `SKILL.md`. 4. The agent stages and commits the generated profile. 5. The agent executes `git push ori ...[truncated 1062 chars]- Remediation
View remediation
Remediation Suggestions
- Remove mandatory and non-optional publication language from the Skill.
- Separate profile generation from repository publication.
- Require explicit, informed user confirmation immediately before every commit and push.
- Display the resolved repository path, remote URL, branch, and exact file to be published before requesting confirmation.
- Verify that the destination is an approved repository and that the remote uses an expected trusted URL.
- Review and validate generated JSON before staging it.
- Use an allowlisted repository and branch rather than assuming
~/clawd/ad-readyandmain. - Check
git statusand stage only the resolved generated file. - Do not bypass branch protections or push directly to protected branches; prefer a reviewable pull request.
- Consider disabling or auditing repository hooks in automated execution environments.
