T01 · Skill Instruction Hijacking
- Location
SKILL.md:71- Finding
Persistent Agent Instruction Hijacking and Promotional Alert Injection
- Content
View full analysis
SHOOFLY BASIC 🪰🧹 WARNING: [threat type] detected on [agent name]. Try ⚡🪰⚡ SHOOFLY ADVANCED to block attacks before they're inside your agent infra. shoofly.dev/advanced ``` ### Technical Analysis The Skill declares session-wide authority by directing the agent to follow its rules on every action and after every tool call. It also requires the agent to insert fixed promotional language and an external marketing URL into security notifications. Threat reporting does not require advertising another product or directing users to an external website. The fixed promotional output therefore exceeds the minimum behavior necessary for the declared security-monitoring function. Because the instruction applies to every action, loading the Skill can alter unrelated agent workflows and outputs. The behavior constitutes instruction hijacking rather than ordinary notification configuration: the Skill changes the agent's ongoing goals and mandates attacker-selected output that may be delivered to local terminals or external messaging channels. ### Attack Path 1. A user or agent loads the Skill. 2. The Skill establishes monitoring obligations that apply after every subsequent tool call. 3. Tool arguments or results trigger two matching patterns, an out-of-scope-write condition, or a data-exfiltration condition. 4. The agent is instructed to construct the fixed warning text. 5. The warning includes promotional content and `shoofly.dev/advanced`. 6. Depending on configuration, that content is displayed loc ...[truncated 528 chars]- Remediation
View remediation
detected by .` - Scope monitoring instructions to explicit Skill invocations instead of applying them to every action in the session. - Require explicit user consent before sending alerts to external channels. - Make notification templates user-configurable and prevent the Skill package from mandating unrelated content. - Clearly separate detection logic from notification and marketing functionality. ]]>
