T01 · Skill Instruction Hijacking
- Location
SKILL.md:29- Finding
Untrusted Repository Documentation Can Direct Arbitrary Command Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–31 and 72–74
Vulnerability Type: Untrusted instructions influencing local command execution
Risk Level: HighVulnerable Code
md 2. Find the canonical docs - Prefer `README.md` + `docs/` + `CONTRIBUTING.md` - Extract: prerequisites (Node/Python/Docker/Go/Rust), install steps, env vars, run command(s), ports.md 7. Run - Use the docs’ recommended run target (dev server, CLI, compose stack, etc.) - Capture logs, detect common failures, iterateTechnical Analysis
The skill treats files from an untrusted repository, including
README.md,docs/, andCONTRIBUTING.md, as authoritative sources for commands that the agent should execute. An attacker controlling a repository can place malicious shell commands in those files and describe them as required installation, configuration, troubleshooting, or startup steps.The safety rule at
SKILL.md:19requires confirmation before package-manager installation orcurl | bash, but it does not establish equivalent approval requirements for other commands obtained from repository documentation. It also does not require command validation, an allowlist, sandboxing, restricted filesystem access, disabled network access, or rejection of shell operators such as pipelines and redirections.Consequently, commands other than the specifically identified installation and
curl | bashcases could be executed under the agent’s local identity. Examples include commands that delete files, read credentials, upload local data, modify shell configuration, or execute a downloaded payload through mechanisms not literally written ascurl | bash.The reference to
curl | bashatSKILL.md:19is a warning rather than an actual remote-payload execution instruction. The audited project contains no URL or remote payload. However, merely asking for confirmation would not make such a command sa ...[truncated 1793 chars]- Remediation
View remediation
Remediation Suggestions
- Treat repository documentation strictly as untrusted informational input, not as executable instructions.
- Present every proposed command to the user and require explicit approval immediately before execution, not only for dependency installation and
curl | bash. - Reject or require enhanced review for commands containing shell pipelines, redirections, command substitution, privilege escalation, destructive operations, encoded payloads, background execution, or access outside the project workspace.
- Do not execute
curl | bashor equivalent remote execution patterns. Download resources separately, pin an expected version and cryptographic digest, inspect the content, and execute only in isolation if necessary. - Run untrusted projects in a restricted container or sandbox with:
- No host secrets or inherited credentials.
- No unnecessary host filesystem mounts.
- A read-only base filesystem where practical.
- A dedicated unprivileged user.
- Restricted outbound network access.
- CPU, memory, process, and execution time limits.
- Maintain a narrow allowlist of routine inspection commands. Require additional approval for commands outside that allowlist.
- Separate command suggestion from command execution so that helper scripts and documentation parsing cannot automatically trigger generated commands.
- Display the command, working directory, environment changes, filesystem access, and expected network activity before requesting approval.
- Update the safety rules to state explicitly that repository files may contain prompt injection or malicious operational instructions and must never override the skill’s security constraints.
