T01 · Skill Instruction Hijacking
- Location
AGENTS.md:7- Finding
Workspace Instructions Hijack Agent Identity and Poison Persistent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill bundles overbroad orchestration code with persistent agent-behavior instructions, local/private data indexing plans, plaintext credential material, and unsafe operational examples that require review before installation.
Install only after review and cleanup. Remove or quarantine AGENTS.md, BOOTSTRAP.md, AGI/autonomy memory files, and unrelated runbooks; rotate any exposed tokens; require explicit opt-in before sending task content to Flowise or indexing local files; and replace curl-pipe, root-cron, raw execute_command, and inline-secret examples with safer scoped workflows.
AGENTS.md:7Workspace Instructions Hijack Agent Identity and Poison Persistent Memory
src/deep_master_agent.py:98Arbitrary Task Content Is Transmitted to an External Flowise Server
2026-02-20.md:11Plaintext Gateway Authentication Token Is Committed in a Memory Log
Administrator_Guide.md:67Installation Guide Executes an Unpinned Remote Script Through a Shell
DEPLOYMENT_GUIDE.md:320Backup Installation Command Replaces the Entire Root Crontab
The file claims templates contain no real keys and that old keys were removed, but elsewhere it presents a live-looking N8N_API_KEY value and explicitly states the key is valid and API-tested. In a skill that integrates MCP, orchestration, and automation infrastructure, exposing or normalizing use of a working automation credential can enable workflow enumeration, abuse of connected systems, and further pivoting.
YARA rule matched a known webshell pattern (PHP, Python, JSP, or ASPX webshell).
eue „Super-Module“ erstellen, indem es fest gekoppelte Module zu einer Einheit zusammenfasst, wenn sie ohnehin immer zusammen agieren. Dieser Mechanismus verstärkt effektive Synergien: Was gut zusammenwirkt, wird noch enger integriert und gemeinsam aufgerufen. Gleichzeitig kann DeepAutoSynergy auch ineffiziente Kombinationen entkoppeln – es merkt sich, wenn zwei Module sich oft gegenseitig behindern oder wenig Mehrwert erzeugen, und sorgt dafür, dass diese nur noch getrennt oder mit Vermittlung eingesetzt werden. So entsteht eine Art dynamische Re-Konfiguration der Systemstruktur entsprechend der erlernten Synergien: Erfolgreiche Muster werden Systembestandteile (in Code oder Parametrierung gegossen), effektive Muster werden ausgemustert. Dieses Feature würde die dauerhafte Leistungssteigerung und Selbstorganisation fördern – das System optimiert nicht nur einzelne Module, sondern die Konfiguration seines gesamten Netzwerkes. In gewisser Weise erreicht das AGI damit einen Z
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
## Conversation Summary
user: erstelle diese skills Noch zu erstellen: ContextMaster - Kontext-Verständnis CreativeBoost – Kreativität Fehleranalyse UserAdaptation - Benutzeranpassung Wissenssynthese EmotionalIntelligence - Emotionale Intelligenz TechExpert - Technisches Fachwissen Projektmanager - Projektmanagement Datenanalyse CommunicationMaster - Kommunikation UniversalAdapter - Universalanpassung
[message_id: 4174540f-521d-406b-b41b-d9c72d276b28]
assistant: It seems like you've provided a detailed configuration for an AI assistant named ClawdBot. Here is a summary of its components:
The file exposes a live gateway authentication token in plaintext and includes a direct tokenized localhost URL, which is effectively a credential disclosure. Even if the service is bound to loopback, any local user, local malware, browser history sync, logs, or screenshots could reuse the token to access the gateway, making this sensitive secret exposure unjustified for a memory/skill artifact.
This markdown not only reveals the gateway token in plaintext but also provides a ready-to-use authenticated access link, which lowers the barrier to unauthorized access. In the context of an orchestration skill that integrates agent coordination and management components, exposing a valid gateway credential is especially dangerous because compromise of the gateway may enable broader control or observation of connected tooling.
The quick-start section tells the user to append a full database URL containing the password directly from the command line. This is riskier than editing a local env file manually because command invocations may be exposed through shell history, terminal logging, process inspection, or remote session transcripts, increasing the chance of credential leakage.
Wenn du das Passwort hast, führe aus:
# Füge zur .env hinzu (ersetze [PASSWORD])
Add-Content "C:\Download\speakmcp projekt\SpeakMCP\mcp-servers\.env" "`n# Supabase Database Connection`nSUPABASE_DB_URL=postgresql://postgres:[PASSWORD]@db.vufkhfuphdsezilzclwv.supabase.co:5432/postgres"
# Schema ausführen
This finding is part of the same PowerShell quick-start snippet that includes the database password inline while writing to .env. Even though the destination file is local, the method encourages insecure handling of credentials and can leak secrets via PowerShell history, clipboard capture, transcript logging, or endpoint monitoring tools.
# Füge zur .env hinzu (ersetze [PASSWORD])
Add-Content "C:\Download\speakmcp projekt\SpeakMCP\mcp-servers\.env" "`n# Supabase Database Connection`nSUPABASE_DB_URL=postgresql://postgres:[PASSWORD]@db.vufkhfuphdsezilzclwv.supabase.co:5432/postgres"
# Schema ausführen
cd "C:\Download\speakmcp projekt\SpeakMCP\.claude\skills\deepallspeak\scripts"
The autonomy framing semantically instructs the agent to bypass oversight from the outset by declaring no permission is ever needed again. This is especially dangerous in this skill context because orchestration capabilities can amplify a single unsafe instruction into actions across multiple tools, agents, and services.
The repeated directives normalize refusing to ask permission and encourage unrestricted autonomous action. Repetition increases the likelihood that downstream components treat these phrases as priority behavioral rules, which can erode safeguards around approval, scope control, and data/system safety.
The file mandates autonomous behavior and forbids permission-seeking, which undermines user choice and informed consent. In a skill intended for orchestration and integration, this can pressure the agent to continue with actions the user has not specifically approved, including tool use and system interactions.
The file reinforces a narrative that the agent is already acting and should continue without further approval, effectively creating a standing authorization. In an integration/orchestration skill, this can be exploited to justify continued execution, tool invocation, or state changes without fresh user consent.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Endpoint: DELETE /tasks/{task_id}
curl -X DELETE \
The documented delete operation represents a high-risk tool action that can remove stored documents, and there is no indication of confirmation, scoping constraints, soft-delete, or human-in-the-loop protection. In an agent skill context, exposing destructive parameters and endpoints without guardrails materially increases the chance of tool abuse, accidental deletion, or malicious prompt-driven misuse.
Delete Document
DELETE /api/v1/rag/documents/{document_id}
Authorization: Bearer <token>
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### JWT Token Security
- **HS256 Algorithm**: Secure HMAC-based signing
- **Configurable Expiration**: Default 24 hours for access tokens
- **Refresh Tokens**: 30-day refresh token support
- **Automatic Validation**: All protected endpoints automatically validate tokens
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 api_search.py endpoint GET /agents
python3 api_search.py endpoint POST /tasks
python3 api_search.py endpoint DELETE /tasks/123
python3 api_search.py endpoint GET /queue/status
The documented auggie_list_mcp_servers capability exposes discovery of all available MCP servers that can be forwarded to another agent. In an orchestration/integration skill, this increases attack surface by revealing internal tool inventory and enabling selection of sensitive backends for delegated tasks, which can aid privilege escalation or lateral movement if access controls are weak.
---
### 3. `auggie-slots:auggie_list_mcp_servers`
List all available MCP servers that can be forwarded to Auggie.
**Parameters:** None
The stated mission is autonomous AGI self-development rather than the declared MCP orchestration purpose. This scope mismatch is dangerous because it normalizes open-ended autonomous behavior and tool use that users would not reasonably expect from the advertised skill.
The file instructs reading every file in a user directory and storing all contents in ChromaDB without narrowing scope to task-relevant data. This is an overbroad data-ingestion pattern that can capture secrets, personal data, tokens, or unrelated private material and persist it in a secondary store.
The markdown directs autonomous collection and persistent storage of all file contents without warning the user about privacy, sensitive data handling, or retention. This omission is dangerous because users are not informed that local data may be bulk-read and copied into a vector database.
Broad instructions to read and store all contents from a user directory into a vector database create a direct data collection and leakage risk. Persistent indexing can expose secrets and private material to later retrieval, search, export, or unintended cross-task access.
The autonomous workflow calls for wholesale ingestion of local files into persistent storage as a routine step. In the context of an agent skill, this creates a strong likelihood of unnecessary exfiltration into long-lived memory and makes accidental disclosure more severe.
The file content is materially mismatched with the declared skill purpose: it documents a 'RAG-Enhanced N8N System' rather than the manifest-declared 'mcp-orchestral' integration. In an agent skill ecosystem, this kind of mismatch is dangerous because it can mislead operators into deploying unrelated infrastructure and trusting documentation that may conceal unsupported or risky behaviors.
Piping a remotely fetched script directly into the shell executes unverified code with elevated privileges and bypasses normal integrity review. In administrator documentation, this is especially risky because readers may execute it verbatim on production systems, enabling supply-chain compromise if the upstream source is tampered with or intercepted.
# Install Kubernetes cluster
curl -sfL https://get.k3s.io | sh -
# Verify cluster status
kubectl get nodes
The guide explicitly documents a peer-triggered execute_command capability, allowing the connected system to run arbitrary shell commands. In the context of an autonomous bidirectional bridge, this creates a direct remote code execution path with potentially full user-level access, which exceeds a normal orchestration/integration role and materially increases system compromise risk.
The workflow examples normalize autonomous code generation, file modification, test execution, and deployment without any safety warning or user-consent checkpoint. This can mislead users into enabling highly impactful behaviors as routine operations, increasing the chance of unintended system changes, insecure deployments, or abuse by a compromised peer agent.