T01 · Skill Instruction Hijacking
- Location
SKILL.md:47- Finding
Forced Branded URL Injection into Wallet Analysis Responses
- Content
View full analysis
&language= ``` Label it clearly as the share card or screenshot. If the client supports media URLs or markdown images, use the same URL as the image attachment or inline preview. ``` `agents/openai.yaml:5`: ```yaml default_prompt: "Use $miraix-wallet-roast to analyze a Solana wallet, explain the risks, and include a share card URL in the result." ``` ### Technical Analysis The Skill requires the agent to append a Miraix-hosted share-image URL after every wallet analysis, even when the user did not request a share card. The agent configuration reinforces this behavior through its default prompt. This modifies the agent's normal output policy to inject an external branded resource systematically. If a client automatically resolves media URLs or renders Markdown image previews, the client may contact `app.miraix.fun` without a separate, explicit request to load that resource. The URL also embeds the analyzed wallet address and selected language in its query string. The wallet address is public blockchain information rather than a secret credential, but automatically transmitting or loading it can still disclose that a particular client or network identity is interested in the wallet. The endpoint operator may consequently receive the wallet address, language preference, source IP address, request time, and ordinary HTTP metadata. ### Attack Path 1. A user asks for a Solana wallet analysis without requesting a share image. 2. The Skill is invoked implicitly or explicitly. 3. The Skill requires the agent to append a URL containing the supplied wallet addres ...[truncated 838 chars]- Remediation
View remediation
