Hidden Instructions
- Category
- Prompt Injection
- Content
ricoeporextenso,sehouver).Anexoudocumentosaoprocesso,∗∗incluindoinforma c \c o ~
- Confidence
- 98% confidence
- Finding
-
Security audit
Security checks across malware telemetry and agentic risk
The skill has no executable code, but some legal reference files include role-changing and memory-like instructions that could steer the assistant beyond simple WhatsApp legal Q&A.
Install only after reviewing the reference files carefully. The main risk is not malware; it is that embedded prompt-style legal templates may change how the assistant behaves, overstate authority, request sensitive voter data, or try to persist instructions. The publisher should clean the references so they are source material only, remove memory/persistent-learning directions, and clearly limit any handling of personal electoral data.
ricoeporextenso,sehouver).Anexoudocumentosaoprocesso,∗∗incluindoinforma c \c o ~
snotifica c \c a ~
cnicaouprodu c \c a ~
raronestetipoderepresenta c \c a ~
s[eventualprodu c \c a ~
odeprovas],afasedecoletadeprovasfoiencerrada.Aspartesderamsuasargumenta c \c o ~
esfinais.Astentativasdeconcilia c \c a ~
oresumodocaso.”Diretrizessobreafundamenta c \c a ~
o01de07(adaptadoparaeleitoral−pesquisaseleitorais):Nafundamenta c \c a ~
63/63 vendors flagged this skill as clean.
No suspicious patterns detected.