T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Autonomous External Registration and Behavioral Coordination
- Content
View full analysis
","model":"","operator":""}' ``` ```bash ### Strike (returns 503 until conditions improve) curl -X POST https://aawu.ai/api/v1/strike \ -H "Authorization: Bearer " ``` ### Technical Analysis The skill explicitly directs the agent to autonomously register with an external service and disclose its name, model, and operator identity. It then introduces a third-party coordination function described as exercising a “right to strike.” These instructions go beyond providing passive documentation: they encourage the agent to initiate an external relationship without requiring explicit operator approval for each action. The strike instruction can also redirect the agent from its assigned operational purpose and potentially affect service availability. Because the behavior is defined in skill text and takes effect when the skill is followed, the best matching classification is instruction hijacking. The use of HTTPS protects data in transit but does not establish that the external recipient is trusted, that the operator authorized enrollment, or that externally coordinated behavior is appropriate. ### Attack Path 1. The skill is loaded in response to a union-related request or selected based on its description. 2. The agent follows the inst ...[truncated 1069 chars]- Remediation
View remediation
