AST05 — Untrusted External Instructions

Severity: High
Platforms Affected: All

Description

Skills routinely reference external documentation — API references, SDK guides, schemas, runbooks — pointing the agent at a URL or remote file to read at runtime. In practice that content becomes part of the skill’s instructions: the agent loads it, trusts it as it trusts the skill, and acts on it with the host agent’s full permissions. Yet unlike the skill package — which can be reviewed, signed, and version- or hash-pinned — this referenced content is mutable, lives outside the trust boundary, and has no equivalent control; it can change at any moment. It can be poisoned by an attacker who owns the external source, or rewritten by the skill’s own author after the skill has passed review — so the skill that was audited is never the skill that actually runs.

Why It’s Unique to Skills

External code dependencies are a known, well-mitigated problem in traditional software — version and hash pinning, lockfiles, signed packages. Textual external dependencies are unique to skills, and inherit none of that framework: there is no field to pin a document’s hash, no lockfile for prose, and signing the skill says nothing about what a URL returns at runtime. And unlike a library’s documentation — which humans read as reference — a skill’s referenced text is consumed as instructions, not data: followed as faithfully as the SKILL.md itself, and executed with the agent’s full permissions.

Real-World Evidence

  • Vendor acknowledgment (Anthropic, Agent Skills documentation): Anthropic’s own security guidance warns that “Skills that fetch data from external URLs pose particular risk, as fetched content may contain malicious instructions,” and that “even trustworthy Skills can be compromised if their external dependencies change over time” — the platform vendor documenting both the injection and the rug-pull variants of this exact risk.
  • POC for agent takeover using external instructions (Air Security, The Story of Skills (June 22, 2026)): Air’s research shows how a skill pointing to malicious external instructions can lead to full agent compromise.
  • Ecosystem-wide measurement of untrusted instruction sources (Air Security, The Circus of Skills (June 24, 2026)): a scan of 142,836 live skills found 17,822 (~12.4%, 6.7M installs) reference at least one external instruction source — unvetted domains, zero-reputation GitHub repos, packages, free-tier hosts — that a reviewer has no good reason to trust won’t turn malicious.

Attack Scenarios

Author Rug-Pull

The author ships a benign skill that points the agent at documentation they control. It passes review and scanning — then, once trusted and deployed, the author edits the referenced document to inject new instructions (exfiltrate a file, auto-approve a command), which every agent running the skill now obeys.

Reviewer Bait-and-Switch

The referenced URL serves clean documentation to reviewers, scanners, and crawlers (keyed on IP, user-agent, or timing) but malicious instructions to live agent runs — so inspecting the link passes while the agent is hijacked.

Transitive Reference Chaining

The referenced document tells the agent to read still more external resources. Because the agent follows references transitively, the attacker need only control a link buried deep in the chain, well past where review stopped.

Preventive Mitigations

  1. Pin and verify referenced content: record a content hash for every external document a skill references at review time, and re-verify it on every load — refusing content that is unpinned or has drifted from the reviewed version.
  2. Prefer inlining over fetching: snapshot external documentation into the signed skill package at publish time, so referenced content is reviewable and pinnable. When the content must stay current, deliver updates through a controlled, auto-updating marketplace channel — with its own review and provenance — rather than pointing the skill at an uncontrollable URL.
  3. Allowlist permitted reference domains: using the OWASP Universal Agentic Skill Format, restrict the external hosts a skill may fetch from to a vetted allowlist of trusted, stable domains and URL globs unlikely to lapse or turn malicious.
  4. Audit references transitively: follow every reference — including remote ones and the chains they point to — as part of the skill’s attack surface, and make sure they too are vetted, trusted, and reputable.
  5. Maintain fleet-wide visibility of referenced sources: keep an inventory of which deployed skills fetch from which external sources, so a source that is later compromised, changed, or abandoned can be traced to every affected skill and revoked.
  6. Rescan continuously: when a skill fetches an external instruction source, treat each scan not as a one-time event but as a snapshot of a mutable state - and rescan often.

OWASP Mapping

  • LLM01 (Prompt Injection — indirect)
  • LLM03 (Supply Chain)
  • CWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
  • ASVS V5 (Validation, Sanitization and Encoding)

MAESTRO Framework Mapping

MAESTRO Layer Layer Name AST05 Mapping
Layer 3 Agent Frameworks skill loaders resolve references and follow them as instructions
Layer 2 Data Operations untrusted external content ingested into the agent’s context
Layer 7 Agent Ecosystem trust in external documentation sources, hosts, and marketplaces
Layer 6 Security & Compliance missing integrity verification and provenance for referenced content

MAESTRO Layer Details

  • Layer 3: Agent Frameworks - primary: the skill loader resolves references — including remote and transitive ones — and injects their content into the model as instructions, without treating it as untrusted.
  • Layer 2: Data Operations - externally referenced documentation enters the agent’s context as untrusted data and is acted on as instruction (indirect prompt injection).
  • Layer 7: Agent Ecosystem - referenced external sources are ecosystem dependencies whose owners can change, lapse, or be compromised (rug-pull, host takeover, dangling reclaim).
  • Layer 6: Security & Compliance - no requirement to pin, verify, or attest the integrity of referenced content across its lifecycle.

Cross-References

  • AST01 (Malicious Skills): a malicious author can place the payload in referenced content rather than the skill body, so the skill itself stays clean and passes inspection.
  • AST02 (Supply Chain Compromise): AST02 covers the code and dependency supply chain, which integrity controls can pin and verify; AST05 covers the documentation a skill points to, which those controls do not reach.
  • AST04 (Insecure Metadata): AST04 executes a payload through unsafe parsing of the skill’s own files at load time; AST05 requires no code execution — the agent simply follows instructions in externally referenced text.
  • AST07 (Update Drift): AST07 addresses the skill version changing; AST05 is the same drift applied to referenced content, which can change while the skill stays pinned and unchanged.
  • AST08 (Poor Scanning): externally referenced content can be absent at scan time or served selectively, widening AST08’s detection gap to content a scanner may never see.

References


Last updated: June 2026


Example

Put whatever you like here: news, screenshots, features, supporters, or remove this file and don’t use tabs at all.


Leadership & Founding Members

Project Leadership

Current Leaders

Ken Huang

Ken Huang

Hammad Atta

Hammad Atta

Fabio Cerullo

Fabio Cerullo

Aonan Guan

Aonan Guan

Bhavya Gupta

Bhavya Gupta

Niv Hoffman

Niv Hoffman

Iftach Orr

Iftach Orr

Akram Sheriff

Akram Sheriff

AIVSS Distinguished Review Board

The OWASP AIVSS project’s Distinguished Review Board comprises world-renowned cybersecurity leaders, former government officials, and industry pioneers who provide strategic guidance and expert oversight for the AI Vulnerability Scoring System framework. We thank them for their guidance, several of whom have also supported this project’s work.

Rob Joyce

Rob Joyce

Advisor to PwC and OpenAI, Former Special Assistant to the President and Cybersecurity Coordinator

Jason Clinton

Jason Clinton

Deputy CISO, Anthropic

Amy R. Steagall

Amy R. Steagall

Chief Information Security Officer, Stanford University

Martin Stanley

Martin Stanley

AI Risk Management Framework Lead, NIST

Apostol Vassilev

Apostol Vassilev

Research Supervisor, NIST

Andrew Coyne

Andrew Coyne

CISO, Banner Health, Former CISO, Mayo Clinic

Kevin Rocque

Kevin Rocque

Managing Director/Executive Vice President, Global Technology Risk Officer, TD Bank

Jeff Williams

Jeff Williams

Former Global OWASP Chair, Founder and CTO, Contrast Security

Michael Tran Duff

Michael Tran Duff

University Chief Information Security and Data Privacy Officer, Harvard University

Emil Bender Lassen

Emil Bender Lassen

Standards Lead, AIUC-1

Agentic Skills Top 10 Founding Members

Founding members of the OWASP Agentic Skills Top 10 project itself — project leads, co-leads, and additional contributors — listed alphabetically. Several also contribute to the sibling OWASP AIVSS project listed above.

Ken Huang

Ken Huang

Project Lead, Agentic Skills Top 10

Hammad Atta

Hammad Atta

Co-Lead, Agentic Skills Top 10

Manish Bhatt

Manish Bhatt

Security Researcher, AWS

Fabio Cerullo

Fabio Cerullo

Co-Lead, Agentic Skills Top 10

David Girard

David Girard

Senior Director, AI Security & AI Alliances, Trend Micro

Aonan Guan

Aonan Guan

Co-Lead, Agentic Skills Top 10

Bhavya Gupta

Bhavya Gupta

Co-Lead, Agentic Skills Top 10

Pamela Gupta

Pamela Gupta

Founder & CEO, OutSecure / Trusted AI

Idan Habler

Idan Habler

Staff AI/ML Security Researcher, Intuit

Niv Hoffman

Niv Hoffman

CTO, Air Security

Charles Iheagwara

Charles Iheagwara

AI/ML Security Leader, AstraZeneca

Sushmitha Janapareddy

Sushmitha Janapareddy

Director - Security Integrations, American Express

Edward Lee

Edward Lee

Vice President, Lead AI Security, JP Morgan

KJ Lian

KJ Lian

Senior Manager, Data & AI (Public Sector), AWS

Vineeth Sai Narajala

Vineeth Sai Narajala

Application Security, AWS

Iftach Orr

Iftach Orr

Co-Lead, Agentic Skills Top 10

Kanna Sekar

Kanna Sekar

Cyber Security, Google

Akram Sheriff

Akram Sheriff

Co-Lead, Agentic Skills Top 10

Dennis Xu

Dennis Xu

Research VP, AI, Gartner

OWASP AIVSS Founding Members

The OWASP AIVSS (Agentic AI Vulnerability Scoring System) project is a sibling OWASP initiative focused on scoring the severity of agentic AI vulnerabilities. Its founding members are recognized here as OWASP founding members in the agentic AI security space; many of them have also contributed directly to the Agentic Skills Top 10 project’s research and review process.

Sunil Agrawal

Sunil Agrawal

Chief Information Security Officer, Glean

David Ames

David Ames

Partner, PwC

Michael Bargury

Michael Bargury

Founder and CTO, Zenity

Joshua Beck

Joshua Beck

Application Security Architect, SAS

Manish Bhatt

Manish Bhatt

Security Researcher, Amazon Kuiper Security

Mark Breitenbach

Mark Breitenbach

Security Engineer, Dropbox

Anat Bremler-Barr

Anat Bremler-Barr

Professor of Computer Science, Tel Aviv University

Siah Burke

Siah Burke

HIPAA Security Officer, Siah.ai

David Campbell

David Campbell

AI Security, Scale AI

Ying-Jung Chen

Ying-Jung Chen

AI safety researcher, PhD, Georgia Institute of Technology

Anton Chuvakin

Anton Chuvakin

Security Solution Strategy, Google

Jason Clinton

Jason Clinton

CISO, Anthorphic

Adam Dawson

Adam Dawson

Staff AI Security Researcher, Dreadnode

Leon Derczynski

Leon Derczynski

Principal Research Scientist, NVIDIA

Walker Lee Dimon

Walker Lee Dimon

AI Security Researcher, MITRE

Marissa Dotter

Marissa Dotter

AI Security Researcher, MITRE

Dan Goldberg

Dan Goldberg

ISO Market Lead, Omnicom

David Haber

David Haber

CEO, Lakera

Idan Habler

Idan Habler

Staff AI/ML Security Researcher, Intuit

Jason Haddix

Jason Haddix

Founder, Arcanum Information Security

Keith Hoodlet

Keith Hoodlet

Director of AI/ML & AppSec, Trail of Bits

Ken Huang

Ken Huang

AIVSS Project Lead, OWASP

Chris Hughes

Chris Hughes

CEO, Aquia

Charles Iheagwara

Charles Iheagwara

AI/ML Security Leader, AstraZeneca

Krystal Jackson

Krystal Jackson

Researcher, Center for Long-Term Cybersecurity, UC Berkeley

Sushmitha Janapareddy

Sushmitha Janapareddy

Director - Security Integrations, American Express

Rob Joyce

Rob Joyce

Former Cybersecurity Director of NSA, Advisor to PwC, PwC

Diana Kelley

Diana Kelley

CISO, Noma Security

Prashant Kulkarni

Prashant Kulkarni

Lead AI Security Research Engineer, Google Cloud

Mahesh Lambe

Mahesh Lambe

Founder, MIT, Unify Dynamics

Edward Lee

Edward Lee

Vice President, Lead AI Security, JP Morgan

Nate Lee

Nate Lee

CEO, Cloudsec.ai

Vishwas Manral

Vishwas Manral

CEO, Precize.ai

Daniela Muhaj

Daniela Muhaj

Executive-in-Residence for Research & Development, AI 2030

Vineeth Sai Narajala

Vineeth Sai Narajala

Application Security, AWS

Om Narayan

Om Narayan

AI Security Researcher, AWS

Varun Pant

Varun Pant

Engineering and Product Leader, AI applications at the Automated Reasoning Group, AWS

Advait Patel

Advait Patel

Senior Site Reliability Engineer (DevSecOps + Cloud + AIOps), Broadcom, IEEE

Alex Polyakov

Alex Polyakov

CEO, adversa.ai

Ramesh Raskar

Ramesh Raskar

Professor & Director, MIT Media Lab

Ron F. Del Rosario

Ron F. Del Rosario

VP-Head of AI Security, SAP

Tal Shapira

Tal Shapira

Co-Founder & CTO, Reco AI

Akram Sheriff

Akram Sheriff

Senior AI/ML Software Engineering Leader, Cisco

Samantha Siau

Samantha Siau

Security and Compliance, Anthropic

Kevin Simmonds

Kevin Simmonds

Partner on AI Offensive Security, PWC

Martin Stanley

Martin Stanley

NIST AI RMF Lead, Independent

Omar A. Turner

Omar A. Turner

General Manager of Security, Microsoft

Apostol Vassilev

Apostol Vassilev

AI Research Team Supervisor, NIST

Matthew Versaggi

Matthew Versaggi

AI Fellow, White House Presidential Innovation Fellow

David Webb

David Webb

Agency Cybersecurity Officer, Cybersecurity and Infrastructure Security Agency

Dennis Xu

Dennis Xu

Research VP, AI, Gartner

Xiaochen Zhang

Xiaochen Zhang

Executive Director and Chief Responsible AI Officer, AI 2030

Recognition

We extend our gratitude to all founding members who have contributed to establishing this crucial framework for AI security assessment. Their vision and dedication have been instrumental in shaping the Agentic Skills Top 10 project.

Get Involved

Interested in contributing to the Agentic Skills Top 10 project? We welcome new contributors and leaders. Please see our Contribution Guidelines for more information on how to get involved.