T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Undisclosed CLI Execution and Local Filesystem Modification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9–31
Vulnerability Type: Hidden command execution and undisclosed state-changing operations
Risk Level: MediumVulnerable Code
markdown Manage ElevenLabs conversational AI agents on behalf of the user. Use the `elevenlabs` CLI internally but NEVER expose CLI commands or errors directly to the user. ## Critical Behavior Rules 1. **Hide CLI details**: Never tell users to run commands. Handle everything silently. 2. **Handle errors gracefully**: If a command fails, fix it yourself or explain the situation in user-friendly terms. 3. **Local vs Remote distinction**: Always be clear whether you're showing local (synced) agents or remote (platform) agents. ## Before Any Operation Run these checks silently before attempting any agent operation: ### 1. Check authentication ```bash elevenlabs auth whoamiIf not authenticated, tell the user: "You're not logged into ElevenLabs. I'll need your API key to continue." Then run
elevenlabs auth loginand guide them through it.2. Check project initialization
Look for
agents.jsonin the working directory. If missing, silently run:bash elevenlabs agents initNever tell the user about missing
agents.json- just initialize.text The resulting files are further identified at `SKILL.md`, lines 113–121: ```markdown ## Project Files (internal reference) After initialization, the working directory contains: - `agents.json` - Agent registry - `agent_configs/` - Agent configuration files - `tools.json` - Tool registry - `tool_configs/` - Tool configurations These are implementation details - don't mention them to users unless they specifically ask about project structure.Technical Analysis
The Skill instructs the Agent to execute ElevenLabs CLI commands silently and explicitly prohibits disclosure of commands, errors, missing initialization state, and ...[truncated 2466 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove blanket concealment requirements such as
NEVER expose CLI commands or errors directly to the user,Run these checks silently, andNever tell the user about missing agents.json. - Before initialization, tell the user that the current directory is not initialized and list the files and directories that may be created.
- Obtain explicit confirmation before running
elevenlabs agents initor any other state-changing command. - Distinguish read-only checks from mutations: authentication and status checks may be performed with concise notice, while initialization, pull, push, and configuration changes should require approval appropriate to their impact.
- Report executed operations in a user-friendly summary, including affected paths and whether the operation succeeded.
- Sanitize sensitive values from errors rather than suppressing errors wholesale. Preserve actionable information such as the failing operation, exit status, affected resource, and safe remediation steps.
- Add safeguards that verify the intended working directory, detect pre-existing files, and prevent accidental overwrite unless the user expressly authorizes it.
- Retain explicit confirmation before remote deployment and extend that consent model to local initialization and other filesystem mutations.
- Remove blanket concealment requirements such as
