T01 · Skill Instruction Hijacking
- Location
scripts/analyze.sh:47- Finding
Indirect Prompt Injection Through Untrusted Feed Content
- Content
View full analysis
"$FILTERED_DIR/extracted-items.json" ``` ```bash # Append the extracted content to the analysis task cat >> "$FILTERED_DIR/analysis-task.md" << EOF Total content items: $TOTAL_RAW EOF jq -r '.[] | "### \(.title)\n- Link: \(.url)\n- Source: \(.source)\n- Popularity: \(.hotness)"' \ "$FILTERED_DIR/extracted-items.json" >> "$FILTERED_DIR/analysis-task.md" ``` The default collector obtains these fields directly from external services: ```bash ITEMS=$(jq '[.hits[] | select(.points >= 10)] | map({ title: .title, url: (.url // ("https://news.ycombinator.com/item?id=" + .objectID)), author: .author, points: .points, comments: .num_comments, source: "Hacker News", hn_url: ("https://news.ycombinator.com/item?id=" + .objectID) })' "$HN_FILE") ``` ### Technical Analysis Titles, URLs, authors, and descriptions obtained from Hacker News, Reddit, TechCrunch, Nitter, and RSSHub are attacker-controlled external data. The scripts place these values into Markdown files that are explicitly intended to be processed by an OpenClaw agent. No prompt-level trust boundary distinguishes system instructions from collected content. The generated analysis task does not instruct the model to treat feed fields solely as quoted data, ignore embedded commands, refrain from tool calls, or produce schema-constrained output. Markdown formatting does not neutralize model-directed instructions. A ...[truncated 1672 chars]- Remediation
View remediation
