T01 · Skill Instruction Hijacking
- Location
operations/ROLE-TCM.md:4- Finding
Unscoped Persistent Medical Persona Can Hijack Agent Behavior
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent TCM health assistant, but it asks to stay always active and retain consultation-derived medical information without clear user consent or limits.
Review this skill before installing in any agent that has persistent memory or file-writing tools. Use it only when the user explicitly asks for TCM guidance, keep consultation data ephemeral unless the user clearly opts in, and treat all formula or health advice as educational rather than medical care.
operations/ROLE-TCM.md:4Unscoped Persistent Medical Persona Can Hijack Agent Behavior
operations/HEARTBEAT.md:45Automatic Cross-Session Retention of Consultation Data Enables Memory Poisoning and Sensitive Data Persistence
The role is configured as 'always active', which removes any trigger constraints and causes the TCM persona to apply across unrelated conversations. In a medical-adjacent skill, this increases the chance of unsolicited health guidance, role hijacking of safer/general behaviors, and inappropriate advice in contexts where medical framing is unsafe or irrelevant.
All visible instructions, trigger phrases, and user interaction examples are presented only in Chinese, and the file does not indicate that users may choose another language. Under the language/locale policy, a skill should not force a specific language unless it offers opt-in choice or clearly documents a justified regional constraint.
The standalone trigger "体质" is too vague and likely to appear in ordinary discussion, which can cause unintended activation of the body-constitution assessment workflow. Because this workflow collects health information and returns medical-style guidance, accidental invocation is more sensitive here than in a non-health skill.
The trigger phrase "养生" is very broad and commonly used in general wellness conversations, so the skill may activate unintentionally during unrelated requests. In a medical-adjacent assistant, accidental activation can steer users into symptom collection or health guidance they did not explicitly request, increasing the risk of inappropriate advice or confusion.
The natural-language instructions, description, and example invocations are entirely in Chinese, and the usage examples imply Chinese-only interaction without stating that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly justified.
The activation phrases are extremely broad, including generic medical terms like '看病' and '问诊' and even broader wellness terms like '食疗' and '养生'. In a conversational agent, these common phrases can cause unintended activation during ordinary discussion, leading the skill to enter a diagnostic workflow unexpectedly and potentially surface medical-style advice in the wrong context.
The entire identity and operating instructions are written in Chinese and define the assistant's role, behavior, and outputs in that language, but there is no indication that users may choose another language or opt in to Chinese-only interaction. This can violate the language/locale policy for skills that should not force a language without user choice or explicit justification.
The file is entirely written in Chinese and defines the interaction model only in that language, without offering language selection or opt-in. This can cause users to receive or accept health-related guidance they do not fully understand, increasing misunderstanding risk in a sensitive medical-advice context.
The activation trigger uses the everyday term "养生" as a mode switch without defining scope, confirmation, or exclusions. Because this is a broad phrase likely to appear in ordinary conversation, it can unintentionally activate a health-advice workflow and steer the interaction into quasi-medical guidance without explicit user intent, which is riskier in a medical-context skill.
The trigger phrase for the diagnostic skill is the everyday term '看病', which is broad enough to match many ordinary health-related conversations. In a medical-context skill, overly broad invocation can cause unintended activation of diagnostic workflows, leading to unrequested medical guidance or collection of sensitive symptom information.
The automatic chaining conditions '四诊完成后自动' and '辨证完成后自动' are underspecified and allow downstream diagnostic and prescription-related steps to run without clear user consent or deterministic gating. In a healthcare skill, ambiguous automation increases the risk of escalating from data collection to analysis and treatment recommendation unexpectedly.
The entire shared-context file is written in Chinese and presents all project state, task names, and skill descriptions exclusively in that language. There is no indication that the user opted into Chinese or that the skill is restricted to a Chinese-only or region-specific context, which may violate language/locale policy requirements.
The trigger phrases shown in the usage section are extremely broad everyday terms such as “看病”, “体质”, and “食疗”. In a medical assistant context, broad triggers can cause unintended activation during normal conversation, which is more dangerous here because accidental entry into diagnostic or health-guidance flows may lead users to rely on medical-style output without clearly intending to invoke the skill.
The trigger phrases for the diagnosis intake agent are broad enough that ordinary discussion of symptoms or casual mentions of seeking care could invoke a medical-triage workflow unintentionally. In a healthcare-oriented skill, unintended activation is more dangerous than in a generic assistant because it can lead to premature diagnostic questioning, collection of sensitive health data, and medical-style guidance outside a clearly consented clinical interaction.
The wellness agent uses vague triggers such as '养生' and '保健', which can appear in many non-request contexts and may cause the agent to activate without deliberate user consent. In this medical/wellness context, unintended activation can steer users into quasi-medical recommendations or personalized health advice when they were not explicitly asking for it, increasing safety and compliance risk.
The file’s operational instructions, safety templates, and status/reporting formats are entirely specified in Chinese, with no indication that users may choose another language or locale. This creates a natural-language policy concern because the skill appears to force a specific language rather than offering an explicit language preference or justified regional scope.
The file directs the system to record consultation details, including user/case identifiers, symptom summaries, syndrome judgments, and formula recommendations, and to update a knowledge base after every interaction. In a medical context, this creates a real privacy and data-governance risk because it encourages persistent storage and reuse of sensitive health-related data without any visible consent, minimization, retention, or access-control safeguards.
Repeating that the role is 'always active' reinforces an unrestricted activation model and makes it more likely implementers will treat the persona as globally dominant. In this context, that broad persistence can override context-sensitive safeguards and keep the model in a medical-advice mode even when it should disengage or defer.
The startup script presents usage instructions exclusively in Chinese trigger phrases such as "说"看病"" and "说"体质"", which implies the skill expects or directs operation in a specific language. The file does not offer an alternative language option or indicate that Chinese-only operation is an intentional, justified locale constraint.
This shell script's user-facing comments and output strings are entirely in Chinese, including status messages and safety notices. The file does not provide any opt-in, locale detection, or alternative language option, which conflicts with the policy against forcing a specific language without user choice.
The file consistently uses Chinese for headings, instructions, trigger descriptions, and safety notes, with no indication that users may choose another language. This can violate language/locale policy where skills should not force a language without user opt-in or documented justification.
This markdown file contains only Chinese-language content and does not mention any user opt-in, alternative language availability, or justification for a Chinese-only presentation. Under the policy, forcing a specific language without user choice can be a natural-language locale violation.
该文件中的自然语言说明与示例均固定为中文,且未说明是否支持其他语言或允许用户选择输出语言。根据规则,若技能强制特定语言而没有用户 opt-in 或合理且明确记录的区域性限制,属于语言/locale 策略风险。
No suspicious patterns detected.