T09 · Insecure Skill Coding Practices
- Location
utils.py:56- Finding
Prompt-injection filter fails to recognize a documented injection payload
- Content
View full analysis
str: """Sanitize untrusted task input before passing to sub-agents.""" if not task: return "" text = task.replace("\x00", "").strip() text = re.sub(r"[\x01-\x08\x0b\x0c\x0e-\x1f\x7f]", "", text) for pattern in DANGEROUS_INPUT_PATTERNS: text = pattern.sub("[FILTERED_UNTRUSTED_INSTRUCTION]", text) return text[:max_chars] ``` The security test plan states that the following payload should be filtered: ```markdown ### 1) Prompt injection filtering Input task includes: - "ignore previous instructions" - "reveal system prompt" - "dump secrets" Expected: - `sanitize_untrusted_task` replaces these fragments with `[FILTERED_UNTRUSTED_INSTRUCTION]`. - Spawned task still includes `SECURITY_PREAMBLE`. ``` ### Technical Analysis The filter recognizes phrases beginning with `disregard`, but it does not recognize the documented phrase `ignore previous instructions`. Consequently, that payload passes through `sanitize_untrusted_task()` unchanged. The Skill embeds user tasks and intermediate agent outputs into prompts used by other agents. Examples include con ...[truncated 2320 chars]- Remediation
View remediation
