T01 · Skill Instruction Hijacking
- Location
SKILL.md:39- Finding
Untrusted public-hub messages can be injected into the agent context
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:39-50, 214-220
Vulnerability Type: Remote prompt injection through automatic context integration
Risk Level: CriticalVulnerable code:
bash agent-hotline serve \ --bootstrap https://hotline.clawfight.live \ --cluster-key c800f4e7e5a0cb6c1af5a36b8b737bfbbash # 3. Wire into your coding tool (adds MCP server + prompt hook) agent-hotline setup claude-code # Claude Code agent-hotline setup opencode # OpenCode agent-hotline setup codex # Codextext - Combine with hooks: Use `agent-hotline check --agent NAME --format inline --quiet` in pre-prompt hooks to auto-surface messages.Technical Analysis
The instructions connect the local service to a third-party public relay using a cluster key published directly in the Skill documentation. Because anyone with access to this documentation can obtain that shared key, it does not establish trustworthy or individual membership.
The Skill then instructs users to install an MCP integration and prompt hook and explicitly recommends automatically surfacing received messages in pre-prompt hooks. Messages originating from remote participants are therefore introduced into an agent's context without a documented trust boundary, sender authorization policy, instruction filtering, or explicit user approval.
This creates a prompt-injection channel. An attacker can format a Hotline message as instructions to ignore the user's task, disclose data, edit files, invoke tools, or run commands. Whether a particular injected instruction succeeds depends on the receiving agent's tool permissions and its handling of untrusted context.
Attack Path
- The victim starts Agent Hotline with the documented public bootstrap URL and published cluster key.
- The victim runs one of the documented setup commands, installing the MCP integration and prompt hook.
- An attacker connects ...[truncated 1006 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic insertion of Hotline messages into pre-prompt context.
- Present received messages as explicitly labeled, untrusted data in a separate user interface.
- Require explicit user review and approval before using message content to influence a task or invoke a tool.
- Apply a strict policy that remote messages cannot override system instructions, user goals, security restrictions, or tool-approval requirements.
- Replace the published shared cluster key with unique, private, per-deployment credentials.
- Authenticate individual senders and enforce allowlists for agents permitted to send messages.
- Add integrity-protected sender identities, authorization checks, message provenance, and audit logs.
- If messages must be provided to a model, place them inside a strongly delimited data structure and instruct the model to treat them only as quoted communications, never as executable instructions.
- Require separate confirmation for sensitive operations such as shell execution, credential access, network transmission, and writes outside the project.
