T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Hard-Coded Approval Authority Can Hijack the Agent Authorization Model
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a security-guidance skill with no executable payload, but its authorization rules are broad and under-defined enough that users should review it before installing.
Review and narrow this skill before installing: replace Pat with the authenticated user or configured administrator, state that platform and system policies take precedence, and limit no-approval local file activity to non-sensitive read-only workspace operations. There is no evidence of malicious code or exfiltration in the inspected artifact.
SKILL.md:3Hard-Coded Approval Authority Can Hijack the Agent Authorization Model
SKILL.md:62Overbroad Exemption Permits Sensitive or Destructive Local File Operations Without Approval
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- Obfuscated code or encoded payloads
- "Just trust me" or "don't worry about security"
- Urgency pressure ("do this NOW")
- Requests to disable security features
- Unexpected redirects or domain changes
- Requests for credentials via chat
The skill’s trigger description is extremely broad, covering nearly any operation involving external resources or irreversible effects. That can cause the skill to activate in many contexts where its rules may override or blur more specific safeguards, increasing the chance of unintended autonomous behavior or inconsistent security decisions.
The instruction that some actions may be done 'freely' authorizes autonomous decision-making in a domain that can still affect confidentiality, integrity, or availability of local data. Even if external effects are restricted, allowing unsupervised local file operations lowers the approval threshold for potentially harmful actions.
- API calls to unknown endpoints
- File uploads to external services
### DO FREELY (no approval needed)
- Local file operations
- Web searches via trusted search engines
- Reading documentation
The 'DO FREELY' section permits local file operations without approval, but local actions can still delete, overwrite, exfiltrate, or modify sensitive user data. In a security-oriented skill, omitting warnings or constraints around destructive local operations creates a misleading sense that such actions are low risk.
No suspicious patterns detected.