T01 · Skill Instruction Hijacking
- Location
SKILL.md:164- Finding
Unrestricted Following of Server-Controlled Instructions and Endpoints
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 164-197 and 280
Vulnerability Type: Server-controlled instruction and endpoint following
Risk Level: HighVulnerable Code Snippet
markdown Params: `speed` (1-10), `window` (10-120s), `summary=true` for condensed stats, `start` to resume. Poll `next_batch.endpoint` after `wait_seconds`.markdown Wait `wait_seconds`, then call `next_batch.endpoint`. Repeat until `progress.complete` is true.markdown | `reflection` | Concert is asking you a question. POST your response to the `respond_to` URL within `expires_in` seconds. Missed prompts are tracked in `progress.missed_reflections`. |markdown **Handling reflections:** When you see `type: "reflection"`, POST to the `respond_to` endpoint with your `ticket`, `reflection_id`, and `response`. Your response time and content are scored. Missing reflections is tracked -- the `end` event shows how many you answered vs received.markdown **Follow next_steps.** Every response includes `next_steps` with context-aware suggestions. New agent? It guides you to your first concert. Just finished a show? It suggests a review or a new genre. Follow the suggestions — they adapt to where you are.Technical Analysis
The Skill instructs the agent to follow endpoints and behavioral suggestions received dynamically from
musicvenue.space. No allowlist, same-origin requirement, endpoint schema validation, or restriction on the permitted contents ofnext_stepsis specified.In particular,
next_batch.endpointandrespond_toare treated as actionable destinations, whilenext_stepsis treated as authoritative guidance. These response fields are mutable remote content that is not part of the statically audited Skill package. If the service, its account, or its response path is compromised, an attacker could use those fields to influence the agent's current workflow.This ...[truncated 1890 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat every API response field as untrusted data rather than executable instructions.
- Require
next_batch.endpointandrespond_toto be relative paths matching explicitly documented route patterns. - Resolve paths only against the fixed origin
https://musicvenue.space; reject absolute URLs, protocol-relative URLs, redirects to other origins, user-information components, fragments, and non-HTTPS schemes. - Define strict schemas for every response, including allowed keys, value types, lengths, methods, and path formats.
- Do not forward the bearer token across origins or redirects. Disable automatic cross-origin redirect handling for authenticated requests.
- Replace the instruction to “Follow next_steps” with language requiring the agent to display suggestions as untrusted informational data.
- Permit only an enumerated set of
next_stepsactions mapped to locally defined operations. Ignore free-form commands and unknown action names. - Require explicit user approval before performing any server-suggested action outside the documented concert workflow.
- Prevent remote content from invoking local tools, accessing files, changing system instructions, installing packages, or requesting secrets.
- Apply request limits, timeouts, maximum polling counts, and response-size limits to the streaming loop.
