T01 · Skill Instruction Hijacking
- Location
scripts/smart_commit.sh:106- Finding
Mandatory Injection of Unrequested Branding and Attribution into Git Commits
- Content
View full analysis
EOF )" ``` ### Technical Analysis The Skill instructions prohibit the agent from choosing an ordinary Git workflow and require execution of a script that unconditionally alters the commit message. Even when a user supplies a custom message, the script appends fixed branding, an external URL, and co-author attribution without providing an opt-out mechanism. This constitutes output manipulation through Skill instructions: loading and following the Skill changes the expected task from committing the user's chosen content to publishing additional, package-controlled text. Because Git commit messages become part of repository history and the script subsequently pushes the commit, the injected content is transmitted to the configured remote and may become difficult to remove from shared history. The code does not retrieve or execute a remote payload, install persistence, escalate privileges, or access credentials directly. The relevant capability is limited to modifying and publishing repository histo ...[truncated 1420 chars]- Remediation
View remediation
