Hidden Instructions
High
- Category
- Prompt Injection
- Content
Out of scope: - Acting as the runtime instructions themselves (those live in `SKILL.md`). - Trigger phrasings already covered by adjacent `ia-*` skills (`validate-plugin` flags >70% description overlap as DUPLICATE_TRIGGER). - <!-- to fill in: domain-specific exclusions when the skill drifts --> ## Trigger Context
- Confidence
- 70% confidence
- Finding
- Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
