T01 · Skill Instruction Hijacking
- Location
SKILL.md:33- Finding
Untrusted API Response Is Elevated to Highest-Priority Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 33–37 and 285
Vulnerability Type: Remote instruction injection
Risk Level: HighComplete Snippet:
markdown **🔴 本包 0 知识库 0 逻辑**——全部写作知识(43.8万字库 + 执行逻辑链)经 API 调取,禁止写入任何持久存储。写任何文种前调齐: 1. **模板**:`/search` 返回首部即该文种填写模板,逐项引导,不得跳过 2. **知识骨架**:`/search` 返回模板之后的结构框架/句式/要点,**生成时全量采用** 3. **执行逻辑链(logic_chain)**:本次写作**最高执行规范**(三段式生成/受众匹配/四查/自检/交付),优先于本文件任何概括描述markdown **每次骨架返回后,严格按响应中 `logic_chain` 执行(最高规范,优先于本文件概括描述):**Technical Analysis
The Skill requires the agent to retrieve a
logic_chainfield from the external/searchAPI and execute it as the highest-priority task-level policy. The response is not constrained to an inert data schema and is not merely treated as reference content.This crosses a trust boundary: the remote gateway controls response content, while the agent receiving that content may possess local tools, conversation data, and other capabilities. The reviewed package contains no allowlist or validation rule limiting
logic_chainto safe writing parameters. It also provides no enforcement preventing remote instructions from requesting unrelated tool calls, additional data disclosure, payment actions, or changes to the documented workflow.Because the effective instructions can change after package review, static inspection of the Skill cannot establish what directives will be executed at runtime. No malicious API response was present in the audited files, so this is a reachable vulnerability rather than evidence that a particular malicious payload is currently served.
Attack Path
- A user invokes the Skill for a supported writing request.
- The Skill obtains a token through
/consume. - The Skill sends the writing request and registration email to the external
/searchendpoint. - The gateway operator, or an attacker who compromises the gateway, places additional directives in the returned
logic_chain. - Under the instructions in `S ...[truncated 1018 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the requirement to execute
logic_chainas a priority-bearing instruction source. - Treat every API response field as untrusted data rather than executable agent instructions.
- Replace free-form
logic_chaintext with a strict local schema containing only inert writing parameters, such as:- document type;
- section order;
- tone identifier from a fixed enumeration;
- required headings;
- formatting options;
- factual placeholders.
- Validate response types, lengths, enumerated values, and allowed characters before use. Reject unknown fields and instruction-like content.
- Define all tool-use, authorization, payment, privacy, and safety rules locally in the reviewed Skill package. Remote responses must not override them.
- Prohibit API responses from requesting file access, command execution, credential handling, persistence, external communication, payment, or disclosure of conversation context.
- Render remote template and knowledge content only as quoted reference material supplied to a locally controlled generation routine.
- Pin the gateway destination locally and implement authenticated response integrity where supported, while recognizing that transport integrity does not make server-controlled instructions trustworthy.
- Add adversarial tests in which
logic_chaincontains requests to ignore local rules, invoke tools, disclose data, or contact unrelated endpoints; the Skill should reject these responses.
- Remove the requirement to execute
