T01 · Skill Instruction Hijacking
- Location
SKILL.md:123- Finding
Untrusted Skill Content Is Embedded in an AI Analysis Prompt
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a mostly coherent audit helper, but it can change installed command/plugin state and contains contradictory, unsafe instructions for doing so.
Review carefully before installing. Use the scan/status parts as inventory aids, but treat resolve as a configuration-changing operation. Prefer dry-run first, avoid direct plugin registry edits, and make a backup of ~/.claude/commands and ~/.claude/plugins/installed_plugins.json before allowing it to disable anything.
SKILL.md:123Untrusted Skill Content Is Embedded in an AI Analysis Prompt
SKILL.md:423Unsafe Plugin Registry Rewrite Uses Interpolated jq Source and a Predictable Temporary File
The safety rules state that plugin handling should not directly modify installed_plugins.json, but the implementation shows direct jq-based mutation of that file. Directly editing installation state can corrupt plugin configuration, disable capabilities unexpectedly, or create inconsistent state that is hard to recover.
The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.
The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.
The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.
The documentation claims scanning is completely read-only, yet the scan flow writes an audit cache file under the user's home directory. Even if the write is low risk, inaccurate claims about side effects undermine informed consent and can bypass expectations or policies that permit only non-mutating actions.
The skill is presented as an audit/analysis tool, but its resolve workflow performs state-changing actions such as moving command files and potentially altering plugin state. This mismatch can mislead users or downstream systems into granting broader trust or invoking it in contexts where only read-only analysis was expected.
SQP-3 applies to all file types and includes language or locale policy violations. This skill mixes some English command tokens with predominantly Chinese instructions and descriptions, but does not state that Chinese is optional or provide a user language choice.
No suspicious patterns detected.