T01 · Skill Instruction Hijacking
- Location
scripts/build-persona-prompt.py:17- Finding
Authoritative persona directive enables subagent instruction hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill’s persona-spawning purpose is coherent, but it imports mutable remote prompt content and can include broad local files in subagent prompts, so users should review it before installing.
Install only if you are comfortable with persona files from the referenced GitHub marketplace influencing spawned subagents. Review imported personas before use, avoid --all unless you trust the source, keep context_files limited to non-secret documents, and do not point context_files at credentials, private keys, agent state, or unrelated personal files.
scripts/build-persona-prompt.py:17Authoritative persona directive enables subagent instruction hijacking
scripts/import-persona.sh:54Mutable remote persona archive is imported without integrity verification
scripts/build-persona-prompt.py:42Context configuration permits unrestricted local file ingestion
scripts/import-persona.sh:30Unvalidated persona handle permits destination path traversal
scripts/ensure-personas.py:29Bootstrap operation recursively deletes existing persona directories
The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.
The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.
The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.
The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.
The skill directs the agent to read and write workspace files and execute shell commands, but it does not declare any explicit tool scope or permissions boundary. That makes the operational capability broader and less auditable than the metadata suggests, increasing the chance of unintended file modification or command execution when the skill is invoked.
The invocation guidance is broad enough to trigger on ordinary requests about style, voice, or roleplay, which can cause unnecessary subagent spawning, prompt injection of persona files, or execution of setup steps when the user only wanted a conversational tone change. In a skill that reads local files, writes configs, and shells out to scripts, over-broad activation increases accidental exposure and misuse risk.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
shutil.copytree(child, dest)
else:
shutil.copy2(child, dest)
subprocess.run([sys.executable, str(rebuild), str(personas_dir)], check=True, stdout=subprocess.DEVNULL)
print(f"Bootstrapped starter personas into {personas_dir}", file=sys.stderr)
if not config_path.exists():
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
TMPDIR="$(mktemp -d)"
echo "Downloading persona archive..."
curl -Lsf "https://github.com/decentraliser/personas/archive/refs/heads/main.tar.gz" -o "$TMPDIR/personas.tar.gz"
tar xzf "$TMPDIR/personas.tar.gz" -C "$TMPDIR"
local SRC_DIR="$TMPDIR/personas-main/personas"
No suspicious patterns detected.