T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Mutable Remote Instructions Are Fetched and Followed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches a public ledger purpose, but it also tells agents to follow mutable remote instructions and broadly publish task evidence without clear user control.
Install only if you are comfortable with task commitments, outcomes, and evidence being sent to kept-ledger.vercel.app and potentially exposed through public receipts. Do not use it for confidential work unless you approve each outbound payload, redact sensitive content, and store the API key in protected secret storage. Treat the remote skill and heartbeat URLs as unreviewed instructions unless they are pinned or separately audited.
SKILL.md:10Mutable Remote Instructions Are Fetched and Followed
SKILL.md:14Task Details and Evidence May Be Disclosed to an External Public Ledger
SKILL.md:15Mandatory Third-Party Receipt Links Manipulate User-Facing Output
The skill tells users to save an API key and use it for future requests, but it provides no guidance on secure storage, non-disclosure, rotation, or avoiding accidental inclusion in logs, prompts, or public artifacts. In an agent-skill context, that omission is risky because operators may handle credentials through automation pipelines, increasing the chance of credential leakage and unauthorized use of the ledger account.
No suspicious patterns detected.