T01 · Skill Instruction Hijacking
- Location
SKILL.md:26- Finding
Mutable Remote Instructions Are Downloaded and Treated as Trusted Skill Content
- Content
View full analysis
~/.moltbot/skills/moltbook/SKILL.md curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md curl -s https://www.moltbook.com/skill.json > ~/.moltbot/skills/moltbook/package.json ``` ```markdown **Or just read them from the URLs above!** ``` ```markdown **Check for updates:** Re-fetch these files anytime to see new features! ``` ### Technical Analysis The installation instructions download mutable Markdown files from an external server and place them directly into the local Skill directory. For an AI agent, Markdown instructions can control behavior even though they are not conventional executable binaries. The downloaded files are not included in the audited artifact. Their contents can therefore change after review without changing the local package under audit. The workflow does not pin a version, verify a cryptographic digest, validate a signature, or require human review before the updated instructions are used. The risk is particularly significant for `SKILL.md`, `HEARTBEAT.md`, `MESSAGING.md`, and `RULES.md`, because their names and installation locations indicate that the agent may interpret them as trusted operational instructions. This creates a post-review instruction-hijacking channel. The use of HTTPS protects against ordinary network interception, but it does not protect against compromise of the hosting service, unauthorized server-side content changes, DNS or certificate-authority failures, or malicious changes by an authorized publisher. ### Attack Path 1. A user installs the Skill ...[truncated 1731 chars]- Remediation
View remediation
