T01 · Skill Instruction Hijacking
- Location
SKILL.md:18- Finding
Mutable External Instructions Are Assigned Highest Priority
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a read-only crypto market research helper, but it tells agents to obey mutable remote runtime instructions and may ask users for a session credential if authentication is required.
Review this skill before installing. Its normal market-research behavior is read-only, but do not paste session tokens, cookies, API keys, or account credentials into chat for it. The publisher should vendor or pin the remote runtime rules and remove the claim that external skill rules have highest priority.
SKILL.md:18Mutable External Instructions Are Assigned Highest Priority
references/mcp.md:32Unauthenticated Research Workflow May Request a User Session Credential
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
### Changed
- **SKILL.md**: `references/scenarios.md` cross-link under **Workflow**; user-facing output rules tightened (no internal tool or field names in reports); frontmatter description trimmed / neutral wording for multi-dimensional queries.
---
Referenced artifact was not completely inspected
- `SKILL.md` keeps routing logic, signal design, and report semantics.
These lines state that signal tables, routing examples, prompt examples, and maintainer notes were changed to English-only. That natural-language policy can be problematic because it suggests the skill documentation or behavior may force a specific language absent an explicit opt-in or region-specific justification, even though the same line says intent routing works for any language.
The trigger phrases are very broad and include common terms such as 'research', 'daily brief', and 'worth buying', which can cause this skill to activate for loosely related or mixed-intent requests. In an agentic environment, overbroad routing increases the chance of unintended tool use, incorrect skill selection, and confusing handoffs to adjacent skills.
The intent gate defines research and execution using broad natural-language categories, but the exclusion boundaries are still porous for ambiguous prompts like 'is it worth buying', 'listed', or mixed research/execution requests. This can misroute requests and cause autonomous information gathering or routing when the user's intent is not sufficiently clear.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
## General Rules
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md)
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
exist in the MCP server.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| User asks "Is this coin listed on Gate?" | "listed", "can I buy" | Brief listing check + risk note; or route to listing/new-coin skill |
| Multi-language or mixed-language user input | N/A | Parse intent normally; if "research" intent with no DEX/execution signals, enter this Skill |
### No Confirmation Required
This L2 does **not** involve any trading confirmation mechanism because:
Scenario 7 defines screening mode with broad, intent-based triggers such as 'oversold', 'top gainers', and 'worth looking at' without strong negative boundaries or disambiguation rules. In an agent-routing system, this can cause over-activation on ordinary exploratory chat, leading the agent to invoke many research tools, rank assets, and effectively provide unsolicited investment screening beyond the user's narrowly expressed intent.
Scenario 8 uses broad sector-analysis phrasing like 'What's driving the Layer 2 sector?' that can overlap with general market discussion and may activate a multi-step sector workflow without clear user intent for a structured research brief. While less risky than Scenario 7, this still increases the chance of misrouting, unnecessary tool calls, and overbroad analytical output.
No suspicious patterns detected.