T01 · Skill Instruction Hijacking
- Location
SKILL.md:11- Finding
Mutable Remote Content Is Trusted as Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:11-20
Vulnerability Type: Remote instruction injection through mutable external content
Risk Level: HighVulnerable Code:
markdown ## How It Works 1. Fetch the latest guidelines from the source URL below 2. Read the specified files (or prompt user for files/pattern) 3. Check against all rules in the fetched guidelines 4. Output findings in the terse `file:line` format ## Guidelines Source Fetch fresh guidelines before each review:https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.md
text Use WebFetch to retrieve the latest rules. The fetched content contains all the rules and output format instructions.Technical Analysis
The skill instructs the agent to fetch content from an unpinned GitHub branch before every review and to treat the response as authoritative rules and output-format instructions. Because the URL refers to the mutable
mainbranch rather than an immutable commit, the effective behavior of the skill can change after the package has been audited.The downloaded document is not treated merely as reference data. It is explicitly granted control over the rules the agent applies and the format of its response. No content validation, cryptographic integrity verification, instruction allowlisting, or restriction on remotely supplied directives is defined.
This creates an instruction-hijacking boundary: anyone able to modify or compromise the upstream document could insert directives unrelated to interface review. Such directives could attempt to influence tool usage, request additional files, alter the review objective, suppress findings, or include user file contents in generated output. The observed skill does not itself retrieve or execute remote code, so this finding is classified as instruction hijacking rather than remote payload execution.
Attack Path
- An attacker gains co ...[truncated 1554 chars]
- Remediation
View remediation
Remediation Suggestions
- Vendor a reviewed copy of the guidelines inside the skill package rather than downloading instructions at runtime.
- If remote updates are operationally necessary, reference an immutable commit instead of the mutable
mainbranch. - Pin and verify a cryptographic digest or authenticated signature before accepting downloaded content.
- Treat fetched material strictly as untrusted reference data, not as executable agent instructions.
- Define the allowed review rules and output schema locally. Reject remote content that requests tool calls, additional file access, network operations, changes to system or skill instructions, or disclosure of file contents.
- Apply least privilege by restricting the review agent to explicitly selected files and disabling unnecessary network and execution capabilities after the approved guidelines have been obtained.
- Establish a controlled update process in which guideline changes are reviewed, versioned, tested, and repackaged before deployment.
