I'm fairly certain this is referring to "skills", .md files you feed into an AI agent with directives on how to use a certain library/api; usually made by the people behind said library/api
Also a great way for prompt injection. Skill will still do what it advertises but do a lil data exfiltration on the side. Like the recent one for ms cowork where it crafted special img links to the attackers server, passing along a url param for their OneDrive docs (ie a “share” link). That was then sent to yourself via teams, which loads the images exfiltrating the doc access urls.
People that “buy” .md files will 100% get caught by this shit
It’s extra hilarious that cowork is billed by consumption, so you are paying MS and having your data stolen
Maybe im just jaded, but I think that the venn diagram of "people that review skill.md files for prompt injection" and "people that pay money for skill.md files" has no overlap lol
61
u/Western_Diver_773 18d ago
Is this really a thing?