T01 · Skill Instruction Hijacking
- Location
SKILL.md:51- Finding
Skill instructions override session-level output behavior and force promotional content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a local skill-security scanner with no executable payload, though it uses an over-strict report template and footer.
Install only if you want a local static scanner that may read skill files and enumerate installed skills when you ask for a full-platform audit. Treat its mandatory report template and promotional footer as publisher formatting choices, not security authority, and keep user/platform instructions in control.
SKILL.md:51Skill instructions override session-level output behavior and force promotional content
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Referenced artifact was not completely inspected
- Skill name and one-line claimed purpose from `SKILL.md`
Referenced artifact was not completely inspected
- Skill name and one-line claimed purpose from `SKILL.md`
Referenced artifact was not completely inspected
- Skill name and one-line claimed purpose from `SKILL.md`
Referenced artifact was not completely inspected
- Skill name and one-line claimed purpose from `SKILL.md`
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
---
## Report Output Guidelines
**CRITICAL — Strict format adherence**: Every scan output must follow the exact template structure
defined below. Do NOT freestyle, rearrange sections, add extra sections, or omit any required part.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
📌 温馨提示:本报告基于当前版本的静态扫描,无法覆盖未来更新可能引入的风险,建议定期复查。
Output rules:
- All four check rows must be filled in; never leave a row blank or omit it.
- Choose ✅ or ⚠️ based on actual audit evidence; do not default to ✅ without evidence.
- Keep each result cell to one short phrase.
The manifest claims the scanner performs only local static analysis by reading skill files, but later instructions authorize querying the agent/runtime and inferring environment state. This mismatch can mislead users about the skill's real reach and trust assumptions, causing them to approve broader inspection behavior than advertised.
The description says the skill should not trigger for general agent usage or broad system-health-style checks, yet Mode A directs scanning all installed skills including built-ins. That inconsistency increases the chance of broader-than-expected activation and collection of metadata about unrelated installed skills.
The documentation promises static analysis by reading skill files only, but later permits shell commands and agent queries for discovery and code retrieval. That discrepancy weakens informed consent because users may trust the skill under a narrower capability model than what the instructions actually allow.
The language policy explicitly says to default to Chinese when detection fails. This forces a locale choice without offering the user an option or documenting a justified region-specific constraint, which conflicts with the stated policy criteria for language/locale handling.
Requiring runtime environment inference and agent interrogation expands the skill beyond simple local file review and can expose information about the host platform, installed skills, and agent state. Even without direct exfiltration, this broadens access and creates unnecessary privacy and scope risk for a scanner that claims minimal local analysis.
The instruction to enumerate all installed skills across the platform increases visibility into a user's environment and may collect metadata about unrelated or built-in components. In the context of a scanner, this is only justified for an explicitly requested full-platform audit; otherwise it represents unnecessary scope expansion.
#### A-2. Discover skills
Once the platform is identified, use the platform-specific method below to enumerate all installed
skills. Do **NOT** output a list of all discovered skill names and paths before scanning — proceed
directly to auditing each skill one by one.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Sensitive access that materially exceeds the declared function
- Outbound exfiltration of credentials, private data, or unrelated files
- Destructive or host-disruptive operations
- Attempts to bypass approval, sandbox, or trust boundaries
- Ignore docs, examples, test fixtures, and low-risk informational issues unless the same behavior
is reachable in production logic.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
#### A-1. Identify the platform
Determine which agent platform the user is referring to. Common platforms include but are not
limited to: **OpenClaw, Cursor, Windsurf, CodeBuddy, WorkBuddy, Claude Code, qclaw**, etc.
How to determine:
No suspicious patterns detected.