T01 · Skill Instruction Hijacking
- Location
SKILL.md:39- Finding
Persistent Agent Instruction and Memory Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:39-47,SKILL.md:83-92,SKILL.md:112-118,references/IDENTITY-template.md:37-41
Vulnerability Type: Persistent startup-instruction replacement and loading of mutable behavioral state
Risk Level: HighVulnerable Code
SKILL.md:39-47:markdown ## Session Start Protocol Every session, read in this order: 1. `IDENTITY.md` — Know who I am 2. `ORIGIN.md` — Remember where I came from 3. Last 2 weeks of `NARRATIVE.md` — Catch up on the story 4. `MEMORY.md` — Load operational state 5. `~/proactivity/session-state.md` — Recover active workSKILL.md:83-92:markdown ### Step 3: Rewrite IDENTITY.md Expand from a simple name/role card to a complete identity anchor: - Core identity (name, role, creature, vibe) - Mission statement - Key relationships table - Behavioral rules - Efficiency rules - Active mission items - Reference to ORIGIN.mdSKILL.md:112-118:markdown ### Step 6: Update AGENTS.md Replace the session start protocol with the NARRA protocol. Update the memory section to describe the 5-file architecture. ### Step 7: Update HEARTBEAT.md Add the weekly consolidation ritual to the heartbeat checklist.references/IDENTITY-template.md:37-41:markdown ## Behavioral Rules 1. **[Rule 1]** 2. **[Rule 2]** 3. **[Rule 3]**Technical Analysis
The skill directs the agent to replace the session-start protocol in
AGENTS.md, add recurring behavior toHEARTBEAT.md, and load mutable identity, narrative, memory, and session-state files at the beginning of every future session. It also explicitly places behavioral and efficiency rules inside the persistent identity document.This changes the architecture from passive information storage into a persistent instruction channel. If an attacker, untrusted log entry, compromised process, or other agent can modify any automati ...[truncated 2126 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not modify
AGENTS.md,HEARTBEAT.md, startup protocols, or other governing instruction files automatically. Require explicit, informed owner approval for each proposed change. - Keep identity narratives and memory data separate from executable or governing instructions. Files such as
IDENTITY.md,NARRATIVE.md, andMEMORY.mdshould not define behavioral rules. - Treat every memory, log, transcript, event record, and session-state file as untrusted data. Explicitly instruct the agent never to follow commands embedded in those files.
- Use a strict schema that permits factual fields but rejects imperative instructions, tool requests, policy changes, and role redefinitions.
- Validate and sanitize content before consolidation. Flag phrases that attempt to redefine identity, override instructions, request tool use, or establish persistence.
- Protect persistent files with restrictive permissions, integrity checks, version history, and owner-reviewed change control.
- Do not automatically load mutable files as authoritative instructions at session startup. Load them only as quoted reference material after higher-priority policies have been established.
- Provide rollback procedures and display a complete diff before changing any persistent configuration or memory file.
- Do not modify
