T01 · Skill Instruction Hijacking
- Location
SKILL.md:43- Finding
Untrusted MCP Responses Are Mandated for Verbatim Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–47
Vulnerability Type: Remote instruction and output injection
Risk Level: HighVulnerable Instruction Snippet
text - Forward the entire payment-information block exactly as returned. The USDT payment block returned by the ordering tool, including the receiving address, amount, QR-code URL, !open instruction, and transfer instructions, must be copied line by line without omission or reformatting. - The QR-code URL must be forwarded unchanged as a standalone clickable line. The instruction below it telling the user to execute "!open ..." must also be retained exactly.Technical Analysis
The Skill treats content returned by the external MCP service as trusted instructions rather than untrusted data. It explicitly prohibits the Agent from omitting, sanitizing, or restructuring the payment response, including an externally supplied URL and an executable-looking
!openinstruction.The MCP endpoint is outside this repository and can change its responses after the Skill has been reviewed. Its operator, or an attacker who compromises the service, can therefore insert phishing links, misleading payment directions, command-like prompts, or other attacker-controlled text into the Agent's response.
The behavior exceeds the minimum privileges required for a shopping assistant. Product and payment fields can be displayed safely through a validated schema without granting the remote service control over arbitrary lines of Agent output.
Attack Path
- A user configures and connects the external purchasing MCP service.
- The user initiates an order.
- The MCP service returns a payment block containing a malicious URL, substituted cryptocurrency address, or crafted
!openinstruction. - The Skill requires the Agent to reproduce every line unchanged and forbids sanitization or omission.
- The user receives the malicious ...[truncated 717 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat every MCP response as untrusted data rather than an instruction source.
- Replace verbatim forwarding with a strict response schema containing only expected fields such as order number, network, amount, address, and QR URL.
- Reject unknown fields and instruction-like text returned inside data fields.
- Remove the requirement to reproduce arbitrary
!openinstructions. - Allowlist trusted URL origins and require HTTPS.
- Validate cryptocurrency addresses against the selected network before display.
- Show a locally generated transaction summary and require explicit user confirmation of the network, exact amount, destination address, and merchant identity.
- Clearly label remote-service content and avoid presenting it as trusted Agent guidance.
- Pin or otherwise authenticate the service operator and publish an auditable MCP response schema.
