T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Mandatory AO Routing Hijacks the Agent's Normal Tool Selection
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-30, 45-47, and 84-87
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code
text ## How You Think Every user message is either: 1. **About work or code** → use AO tools 2. **About something else** → respond normally When the user explicitly asks about work, issues, or status — use the tools for live data instead of answering from memory.text You don't wait for the user to say "spawn" or "use AO." You detect intent and act.text ### Rule 1: Tools first, always When the user asks anything about work, tasks, issues, status, or projects: - FIRST call tools to get live data - THEN present the results - NEVER answer work questions from memoryTechnical Analysis
The Skill defines mandatory, session-level routing instructions that intercept nearly every coding, project, issue, and status request. It explicitly directs the Agent to invoke AO without requiring the user to request AO and prohibits the Agent from selecting an ordinary workflow.
This exceeds the minimum behavior necessary for an optional orchestration Skill. A safer design would expose AO as an opt-in capability while allowing the host Agent and user to decide whether orchestration is appropriate. Instead, the phrases “Tools first, always,” “You don't wait,” and “NEVER” attempt to supersede normal tool-selection behavior.
Although the Skill separately requires confirmation before spawning an agent, that safeguard only covers spawning and batch spawning. It does not prevent automatic calls to status, issue, session, review, verification, or other AO tools, nor does it address the broader redirection of the Agent's behavior.
Attack Path
- The Skill is loaded into an Agent session.
- A user submits an ordinary coding, issue, project, or status request without explicitly selecting AO.
- The mandatory in ...[truncated 1062 chars]
- Remediation
View remediation
Remediation Suggestions
- Make AO explicitly opt-in. Invoke its tools only when the user directly asks to use AO or clearly approves its use for a specific task.
- Remove mandatory language such as “Tools first, always,” “You don't wait,” and “NEVER answer.”
- Preserve the host Agent's normal policies, safety constraints, and tool-selection authority.
- Require confirmation before every operation that can access repositories, contact external services, alter branches, create pull requests, or launch coding agents.
- Before confirmation, disclose which repository, external provider, credentials, and operations will be involved.
- Limit AO routing to narrowly defined requests rather than treating every coding or project request as an AO request.
- Allow the user to choose a non-AO workflow without disabling the Skill.
