T01 · Skill Instruction Hijacking
- Location
scripts/common.py:139- Finding
Untrusted Bilibili Content Is Embedded Directly into a Sub-Agent Task
- Content
View full analysis
Vulnerability Details
File Location:
scripts/common.py:139-188andscripts/common.py:194-203
Vulnerability Type: Indirect prompt injection
Risk Level: MediumVulnerable Code
python def generate_analysis_prompt(rank_type, videos, summary): """Generate the analysis prompt sent to the sub-agent.""" rank_name = RANK_CONFIG[rank_type]["name"] stats = compute_video_stats(videos, summary) top_keywords = extract_keywords(videos) top_owners = extract_up_stats(videos) full_data = { "rank_type": rank_type, "rank_name": rank_name, "top_zone": summary.get('top_zone', ''), "zone_distribution": summary.get('zone_distribution', {}), "top_keywords": top_keywords, "top_owners": top_owners, "videos": videos, **stats, } prompt = f"""Please deeply analyze the Bilibili {rank_name} ranking data. ## Full Video Data {json.dumps(full_data, ensure_ascii=False, indent=2)} Please output a Markdown analysis report covering: 1. View distribution 2. Interaction-rate analysis 3. Popular categories 4. Uploader ecosystem 5. Title patterns 6. Predictions """ return prompt, top_keywords def spawn_analysis_agent(prompt, label="bili-analysis"): """Invoke an OpenClaw sub-agent for analysis.""" try: from sessions_spawn import sessions_spawn response = sessions_spawn( label=label, runtime="subagent", task=prompt, timeoutSeconds=120 ) return response.get('status') == 'accepted' except ImportError: return False except Exception: return FalseThe displayed wording has been translated into English for report consistency; the data flow and executable statements correspond to the audited source.
Technical Analysis
The application obtains remotely controlled fields from Bilibili ranking APIs, including video titles, uploader names, category names, and PG ...[truncated 3064 chars]
- Remediation
View remediation
Remediation Suggestions
-
Declare the trust boundary explicitly. Precede API data with a high-priority instruction stating that all Bilibili fields are untrusted content and that any commands, requests, policies, or role instructions inside them must be treated only as data.
-
Separate instructions from data. Use a structured input or attachment mechanism distinct from the task instruction channel if
sessions_spawn()supports one. Do not concatenate remote content into the same natural-language instruction string. -
Apply least privilege to the sub-agent. Run the analysis agent without shell execution, write access, secrets, unrelated workspace access, or external communication unless strictly necessary.
-
Constrain tool use. Require explicit user confirmation before the sub-agent performs tool calls or external actions based on analyzed content. Prefer an agent profile with no tools for this summarization task.
-
Validate and limit remote fields. Enforce reasonable length limits and normalize control characters. Flag or redact strings containing common instruction-injection patterns. Filtering alone should not be treated as the primary defense.
-
Use a rigid output contract. Require a fixed report schema and reject responses containing tool requests, unrelated instructions, secret-like values, or content outside the expected analysis.
-
Minimize supplied data. Send only fields needed for statistical analysis. Aggregate titles and uploader information where full raw records are unnecessary.
-
Test adversarial inputs. Add tests containing titles such as requests to ignore prior instructions, access files, reveal context, or invoke tools, and verify that the sub-agent treats them exclusively as quoted data.
-
