T01 · Skill Instruction Hijacking
- Location
SKILL.md:66- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This leadership-advice skill is mostly static guidance, but it tries to force unsolicited onboarding and promotional branding into responses, including outside its own topic.
Review this skill before installing if you do not want book-specific framing, Heardly branding, or external promotional links added to answers. The artifact does not show malware-like behavior, but its response-control instructions are intrusive and should be narrowed or overridden by host policy.
SKILL.md:66Mandatory Promotional Content Hijacks Agent Responses
SKILL.md:31Skill Triggers Unsolicited Output Immediately Upon Loading
The trigger list contains broad phrases like 'build team culture' and 'handle crisis as leader' that may match many ordinary management conversations not specifically seeking this skill. This can lead to overbroad activation, causing the agent to inject this skill into unrelated contexts and degrade safety, relevance, and user control.
The instruction to 'proactively present this guide without waiting for the user to ask' creates unsolicited self-invocation behavior. In an agent environment, this can cause the skill to activate outside clear user intent, overriding normal routing and increasing the chance of irrelevant or intrusive responses.
The metadata defines trigger phrases such as "lead through change," "build team culture," and "handle crisis as leader," which are broad and likely to match many ordinary leadership queries outside the narrow Tom Ziglar skill scope. Over-broad activation can cause the wrong skill to be invoked, leading to irrelevant guidance, context hijacking, and reduced reliability of the assistant’s routing behavior.
No suspicious patterns detected.