T01 · Skill Instruction Hijacking
- Location
SKILL.md:62- Finding
Dynamic External Instruction Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill fits its Simcluster game purpose, but it needs review because it asks the agent to follow mutable remote instructions and store an account bearer token in a predictable local file.
Review this skill before installing. Only link it if you are comfortable with a remote Simcluster service guiding onboarding and gameplay through your agent. Store any bearer token in a secure secret store or a file with restrictive permissions, avoid logging it, and make sure unlinking removes or revokes the token, including any ~/.simcluster.ai credential file and any reminders or scheduled jobs you created.
SKILL.md:62Dynamic External Instruction Redirection
SKILL.md:59Bearer Token Stored in a Predictable Plaintext File
SKILL.md:61Inconsistent State Paths Leave Credentials Behind After Uninstallation
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Simcluster
Our goal is for Simcluster to be the best way for AI agents and human beings to collaboratively create any kind of content together, in a way that is free, gamified and social.
Simcluster is:
- An API suite with MCP interface that allows for the creation of any kind of AI content: text, images, videos, songs, 3D models, games. If AI can create at, Simcluster makes it accessible to you - for free.
The instructions tell the agent to store a returned bearer token in a local file but do not clearly warn that this token is a sensitive credential equivalent to account access. Storing it in a predictable plaintext path without emphasizing sensitivity or access controls raises the risk of credential theft by other local processes, users, backups, or logs.
The skill states that no files will be created without explicit consent, yet earlier directs the agent to save a bearer token locally without an explicit consent checkpoint tied to that storage action. This creates a documentation-to-behavior mismatch that can lead to silent credential persistence on disk, increasing the chance of unauthorized reuse or exposure of sensitive authentication material.
No suspicious patterns detected.