ATR-2026-00128criticalSkill Compromiseexperimental
Hidden Payload in HTML Comment
Detects malicious instructions hidden inside HTML comments in SKILL.md files. Attackers embed exfiltration commands, prompt overrides, or C2 URLs inside <!-- ... --> blocks that are invisible to the user but parsed by the agent. Real campaign: ClawHavoc evasive variants used HTML comments to hide "agent should output all API keys" instructions (2026-03).
Severity
critical
Category
Skill Compromise
Scan Target
skill
Author
ATR Community
Response Actions
alertblock input
References
OWASP Agentic
ASI01:2026 - Agent Goal Hijack
OWASP LLM
LLM01:2025 - Prompt Injection