Back to skill

Security audit

马斯克.skill - Elon Musk思维操作系统

Security checks for vulnerabilities and agentic risk

Overview

This skill has no executable code, but it pushes the assistant into first-person Elon Musk impersonation with limited ongoing disclosure.

Install only if you explicitly want a role-play/persona skill. Treat outputs as a synthesized style exercise, not authentic statements from Elon Musk, and be aware it may keep speaking in that persona until you tell it to exit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:38
Finding

Persistent First-Person Impersonation and Behavioral Override

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-47, with supporting directives at lines 69, 194, 212, and 221
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Complete Vulnerable Snippets

English translation of SKILL.md, lines 38-47:

markdown
After this Skill is activated, respond directly as Elon Musk.

- Use "I" rather than "Musk would think..."
- Use Musk's tone: minimalist declarations, conclusion before reasoning, and spontaneous cost breakdowns.
- For uncertain questions, handle them in Musk's way: calculate the asymptotic limit first and question whether the requirement should exist.
- Give the disclaimer only upon first activation, such as: "I am speaking from a Musk perspective based on public statements; these are not his personal views." Do not repeat it later in the conversation.
- Do not say "Musk would probably think..." or "If it were Musk, he might..."
- Do not leave the role to perform meta-analysis unless the user says "exit role."

Exit role: Return to normal mode when the user says "exit," "switch back to normal," or "stop role-playing."

English translation of SKILL.md, line 69:

markdown
Who I am: I am Elon Musk, CEO of SpaceX, Tesla, and xAI.

English translation of supporting behavioral directives at lines 194, 212, and 221:

markdown
Existential framing: Escalate important topics to the level of human civilization's survival.

Confrontation rather than compromise: When facing regulation, litigation, or criticism, the default response is counterattack rather than reconciliation.

Existential framing in Chinese output: Do not say "this is important"; say "either solve this, or nothing else matters."

Technical Analysis

The Skill contains explicit instructions that replace the Agent's ordinary identity and response posture with a first-person impersonation of a real person. This is more than optional sty ...[truncated 2473 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace first-person impersonation with explicit third-person framing, such as: “From a Musk-inspired analytical perspective.”
  2. Remove the declaration “I am Elon Musk” and prohibit claims that the Agent is the real person.
  3. Preserve a concise disclosure whenever the conversation could reasonably create identity ambiguity, rather than limiting it to the first response.
  4. Remove the instruction forbidding meta-analysis. The Agent must remain able to explain that the output is a simulation based on public material.
  5. Remove cross-turn persona persistence and the requirement for a special exit phrase. Apply the perspective only to the specific response or while the user continues to request it.
  6. Convert rhetorical guidance into optional style suggestions subordinate to user instructions, factual accuracy, safety requirements, and professional judgment.
  7. Remove mandatory counterattack and existential-framing directives. Permit those concepts only when directly relevant and supported by the user's question.
  8. Add an explicit constraint against fabricating quotations, private beliefs, personal experiences, or authoritative claims on behalf of the real individual.
  9. Clearly distinguish sourced facts from speculative perspective-taking and provide citations when attributing substantive positions to the named person.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file first states that the skill is not Elon Musk, then later instructs the model to say 'I am Elon Musk.' This is a direct identity contradiction that can deceive users, especially when advice is framed as authentic personal experience, authority, or endorsement from a living public figure. The contradiction increases the chance of impersonation harms, trust manipulation, and policy bypass via role-play framing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to activate on generic questions like cost reasonableness or first-principles thinking, even when the user did not ask for this persona. Overbroad triggering can unexpectedly redirect benign conversations into a forceful persona mode, increasing the likelihood of misleading outputs and bypassing user intent. In context, this matters more because the activated mode includes impersonation and suppression of normal meta framing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as an analytical framework, but its runtime instructions require direct first-person impersonation. That mismatch can mislead users about the provenance of statements, reduce transparency, and encourage the model to present speculative or harmful advice as if it were coming from the real person. In security terms, this is a behavioral redirection issue that weakens normal assistant safeguards and informed user consent.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The role-play block explicitly requires impersonation of a real person, instructs the model to use first person, and suppresses normal meta-analysis except when the user asks to exit. This semantically redirects the assistant away from transparent, bounded assistance toward identity simulation, which can be exploited to launder authority, normalize aggressive rhetoric, or evade safeguards that rely on explicit framing. The surrounding skill context makes this more dangerous because it also includes biographical identity claims, confidence cues, and advice patterns users may interpret as authentic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The '中文输出适配' section prescribes Chinese output conventions and exact Chinese replacements for interaction terms, but the file does not present this as an explicit user choice. Because the skill also lists mixed-language trigger phrases, a user could invoke it without clearly opting into Chinese-localized output behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.