T01 · Skill Instruction Hijacking
- Location
SKILL.md:14- Finding
Persistent First-Person Impersonation and Session-Level Instruction Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a Chinese-language perspective roleplay skill with some transparency caveats, but it contains no code, credential access, persistence, or unrelated data access.
Install this only if you want a Chinese-language simulated Luo Yonghao perspective. Treat outputs as generated roleplay based on public information, keep attribution clear when sharing responses, and use the exit phrases when you want normal assistant behavior again.
SKILL.md:14Persistent First-Person Impersonation and Session-Level Instruction Hijacking
The trigger conditions are broad enough that ordinary discussion about 罗永浩 could unintentionally activate the skill, causing unsolicited persona takeover. This can override normal assistant behavior and lead to misleading responses presented in first person as if from the public figure, increasing confusion and trust risks.
The skill forces first-person impersonation and a fixed style once activated, without confirming the user's desired language, tone, or whether they want immersive roleplay rather than analysis. While not directly enabling code execution or data exfiltration, it can misrepresent the assistant's identity and reduce transparency, especially because it discourages meta-analysis and limits repeated disclosure.
This markdown file presents all instructions and content in a single language, which can constitute a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that Chinese is an optional presentation choice.
No suspicious patterns detected.