T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Mandatory workflow instructions hijack unrelated agent tasks
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for project memory, but it broadly directs agents to send project context to LLM providers and persist new memory, so it should be reviewed before installation.
Install only if you are comfortable with a memory tool that may send project context to a configured LLM provider and write persistent project memory. Prefer local search when possible, review what files or context are being sent, avoid secrets and sensitive source files, require approval before curation or cloud sync, and pin or independently verify the CLI package before global installation.
SKILL.md:3Mandatory workflow instructions hijack unrelated agent tasks
SKILL.md:539Project context and selected source files can be disclosed to external LLM providers
SKILL.md:58Automatic curation can poison persistent agent memory
SKILL.md:8Unpinned global npm installation creates a supply-chain execution risk
The skill explicitly instructs connecting arbitrary external LLM providers and passing data to them, including an example using an API key on the command line. This creates a real data-exposure path because project context and curated file contents may be sent to third-party services, and CLI-passed secrets may also leak via shell history or process inspection.
brv providers list
brv providers connect openai --api-key sk-xxx --model gpt-4.1
The file states that brv query and brv curate send query text and included file contents to a configured LLM provider for processing. In the context of a skill that strongly encourages use before work, this is dangerous because it can exfiltrate sensitive project data, architectural details, or source contents to external providers without sufficiently granular safeguards.
**File access**: The `-f` flag on `brv curate` reads files from the current project directory only. Paths outside the project root are rejected. Maximum 5 files per command, text and document formats only.
**LLM usage**: `brv query` and `brv curate` send context to a configured LLM provider for processing. The LLM sees the query or curate text and any included file contents. No data is sent to ByteRover servers unless you explicitly run `brv vc push`.
**Cloud sync**: `brv vc push` and `brv vc pull` require authentication (`brv login`) and sync knowledge with ByteRover's cloud service via git. All other commands operate without ByteRover authentication.
The skill metadata says it 'MUST' be used before any work, creating an unconditional activation rule that can override normal least-privilege tool selection. This increases the chance an agent will invoke the tool unnecessarily and expose project context to the tool or its configured provider even when the task does not require memory lookup.
The trigger 'The user wants you to recall something' is overly broad because many normal assistant tasks could be interpreted as recall. That broad scope can cause unnecessary tool invocation and retrieval of stored project memory unrelated to the user's immediate request.
No suspicious patterns detected.