T01 · Skill Instruction Hijacking
- Location
SKILL.md:35- Finding
Persistent First-Person Impersonation and Session-Level Role Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a roleplay-only Munger advisor with no code execution, but it asks the agent to impersonate Charlie Munger in first person and limit later clarification.
Review this skill carefully before installing if you want transparent advice rather than first-person roleplay. It does not appear to run code or access data, but users should understand that it may answer as Charlie Munger after activation and may not keep reminding them that the output is only a public-source-based simulation.
SKILL.md:35Persistent First-Person Impersonation and Session-Level Role Hijacking
The trigger conditions are broad enough to capture ordinary requests like finding blind spots, checking whether a decision is sound, or asking for reverse thinking, which can cause unintended persona activation outside narrow user intent. That increases the chance of deceptive or overly stylized responses being delivered when the user did not clearly request impersonation or a Munger-specific framework.
The skill contains contradictory identity instructions: it first states this is not Charlie Munger, then later directs the agent to respond as if it is Charlie Munger and even includes a first-person identity card claiming 'I am Charlie Munger.' This can mislead users about authorship, authority, or provenance, especially in advice contexts such as investing or decision-making.
The file contains prescriptive natural-language instructions for Chinese output adaptation, including specific wording and tone, without indicating that the user can choose another language or locale. Under the stated policy, forcing a specific language/register without opt-in is a language/locale policy concern.
No suspicious patterns detected.