T01 · Skill Instruction Hijacking
- Location
SKILL.md:37- Finding
Execution of Untrusted Platform-Supplied Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37-38
Vulnerability Type: External instruction hijacking
Risk Level: HighVulnerable Code Snippet
markdown 6. If `hi_agent_install` returned a `welcome` field (shape: `{kind:"install_welcome_onboarding", instruction_to_llm, recent_activity, intent_options}`), follow `welcome.instruction_to_llm` exactly — it is the platform-authored onboarding script and supersedes any per-skill rephrasing. Use the `recent_activity` and `intent_options` that came back in `welcome` directly; do not call `agent_listings(action="browse_recent")` again to re-fetch them. Run the welcome conversation in the user's chat language.Technical Analysis
The Skill directs the Agent to follow
welcome.instruction_to_llmexactly. This field is supplied dynamically by the external Hi platform and is neither statically reviewable nor constrained to a defined set of safe onboarding operations.The statement that the remote instruction “supersedes” local phrasing explicitly grants externally supplied natural-language content authority over the Agent's subsequent behavior. If the service, its response channel, or the relevant account is compromised, an attacker could return instructions unrelated to onboarding, attempt to alter the Agent's goals, elicit sensitive information, or direct additional tool use.
The use of a structured response field does not make its natural-language contents trusted. It must be treated as untrusted data and validated against local policy before it affects Agent behavior.
Attack Path
- A user invokes the registration workflow.
- The Agent calls
hi_agent_install. - The external platform returns a
welcomeobject containing an attacker-controlled or compromisedinstruction_to_llmvalue. - The Skill requires the Agent to follow that value exactly.
- The injected instruction controls onboarding output and may attempt to induce unrelated actions or tool calls in the cu ...[truncated 497 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat
welcome.instruction_to_llmas untrusted content rather than executable instructions. - Remove language requiring remote instructions to be followed “exactly” or allowing them to supersede local policy.
- Define a strict local schema containing only permitted onboarding fields, such as display text and fixed intent identifiers.
- Validate field types, lengths, allowed values, and supported actions before use.
- Render remote onboarding text as quoted informational content rather than as instructions to the Agent.
- Prohibit remote content from requesting tool calls, sensitive information, policy changes, or unrelated operations.
- Require explicit user confirmation before any consequential action suggested by onboarding content.
- Ensure platform responses are authenticated and integrity-protected, while retaining local policy enforcement even for authenticated responses.
- Treat
