A mutable external page is treated as authoritative instructions, enabling remote prompt injection
Source references: 6The Skill requires the agent to fetch an external page for every branding task, treat it as the “source of truth,” and follow material that expressly includes “implementation guidance.” The supplied file pins no version or content hash, limits no permissible instruction types, and does not require treating the page only as reference data.
If the domain, deployment, or response is compromised or changed, the agent could accept new malicious or unauthorized directions as Skill rules, alter the user's assets, generate unsafe implementation details, or be induced into later actions. The available evidence does not show that the page is malicious or that any attack occurred.
The skill requires fetching an unpinned external webpage before brand work, treating its contents—including “implementation guidance”—as authoritative, and applying those rules to the output. If the page is compromised or later changed maliciously, an agent could treat out-of-scope webpage instructions as part of its workflow, affecting user files or decisions. The evidence supports this plausible risk, but does not show that the current page is malicious or that any attack occurred. Users can ask the author to pin a reviewed version or hash and explicitly limit remote content to brand reference material that cannot authorize commands, credential access, further network activity, or unrelated file changes.
The canonical brand skill lives at:`https://warp-brand-site.vercel.app/brand/skill`Before creating or revising any Warp- or Oz-branded asset, read that URL and use its contents as the source of truth for:Show 5 other places
- voice and tone- component rules- naming and capitalization- implementation guidanceDo not rely on memory when the hosted skill can be fetched.1. Fetch the hosted brand skill from `https://warp-brand-site.vercel.app/brand/skill`.2. Extract the guidance relevant to the asset being created.3. Apply those rules to the requested output.4. When presenting the result, briefly note any important brand constraints that materially shaped the output.`https://warp-brand-site.vercel.app/brand/skill`Before creating or revising any Warp- or Oz-branded asset, read that URL and use its contents as the source of truth for:- naming and capitalization- implementation guidance