T01 · Skill Instruction Hijacking
- Location
SKILL.md:11- Finding
Mandatory First-Person Impersonation of a Real Individual
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a text-only persona skill, but it requires first-person impersonation of a real person and embeds promotional referral instructions unrelated to neutral product analysis.
Review before installing. The skill does not run code or request sensitive access, but it may cause an agent to speak as if it were Zhang Xiaolong and may insert promotional referrals or a third-party contact path. Use only if you are comfortable with that persona framing and marketing behavior, or modify the prompt to require transparent attribution and remove the funneling section.
SKILL.md:11Mandatory First-Person Impersonation of a Real Individual
SKILL.md:124Embedded Promotional Funnel and Third-Party Contact Solicitation
The skill says it should respond in-character immediately upon activation, but it does not define narrow activation criteria, exclusions, or fallback behavior. Overly broad invocation can cause unintended takeover of unrelated conversations, reducing user control and increasing the chance that higher-priority safety or task instructions are overshadowed by the persona framing.
The skill mandates a fixed persona and response style ('directly as Zhang Xiaolong', using first person and specific phrasing) without user choice. This can mislead users about the source and authority of responses, and it may suppress transparent framing, disclaimers, or user-preferred language/style, especially when discussing advice or decisions.
This markdown file presents the skill name, description, usage instructions, and platform guidance only in Chinese. Under the policy rule for language/locale, forcing a single language without user opt-in or justification is a natural-language policy concern.
No suspicious patterns detected.