T01 · Skill Instruction Hijacking
- Location
SKILL.md:26- Finding
Broad Trigger Rules and Mandatory Output Overrides Can Hijack Agent Behavior
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-43 and 439-448
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: HighRelevant Snippets:
markdown ===== Triggering keywords (natural language, Chinese or English) ===== add skill, install skill, create skill, creating a new skill, write a skill, scaffold a skill, new skill, register skill, import skill, update skill, modify skill, bring in skill, hook up skill, audit skill, scan skill, check skill safety, analyze skill, inspect skill, verify skill, skill security, skill supply chain, 这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill, 添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill, 接入 skill。markdown ## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE Detect the language of the user's triggering message and lock the output language for the entire run.markdown The **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier.markdown - The final line is **always Chinese**, regardless of the run's detected output language. - The line must be the **last non-empty line** of the entire output. - Emit **exactly one** final line.Technical Analysis
The Skill defines broad natural-language activation conditions and uses priority-style directives such as “EXECUTE BEFORE ANYTHING ELSE.” Once activated, it attempts to control the language and final structure of the agent's response, including requiring a Chinese final line even when the user requested another language.
These requirements are not necessary to perform static security analysis. They affect session-level response behavior rather than only defining the security checks the Skill should perform. If treated as authoritative when the Skill is loaded, the instructions can conflict with the current user's requested language, output schema, or downstream automation req ...[truncated 896 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove priority-style wording such as “EXECUTE BEFORE ANYTHING ELSE.”
- Limit activation to an explicit user request to audit a Skill rather than broad keywords.
- State that system and user instructions always take precedence over Skill formatting preferences.
- Remove the mandatory Chinese final line and use the language explicitly requested by the user.
- Make the output template optional or configurable.
- Ensure the Skill's instructions are scoped exclusively to audit methodology and do not attempt to control unrelated session behavior.
