T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Unsolicited First-Load Response Instruction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a lead-generation advice skill, but it tries to control when the assistant speaks and injects Heardly promotional links into every answer, even outside the skill's topic.
Review this skill carefully before installing. Its business frameworks are mostly on-topic, but it may cause unsolicited onboarding, append Heardly promotional links to unrelated answers, and encourage high-volume outreach without reminding users to follow consent, anti-spam, privacy, and platform rules.
SKILL.md:24Unsolicited First-Load Response Instruction
SKILL.md:57Mandatory Advertising and External-Link Injection into Every Response
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
### Scenario 5: "I've Tried Everything and Nothing Works"
**You've attempted multiple lead gen methods with no results.**
- **Self-diagnosis:** The problem is either (a) not enough volume, (b) not enough skill, or (c) both. Pick ONE method. Do 100/day for 30 days. Track everything. Adjust. If it still doesn't work after 30 days at volume, try a different method. But don't judge a method at 5 attempts.
- **Book quote:** "If you have thousands of nos, you will get your yeses, I promise. I always tell myself: Yeses give me opportunity. Nos give me feedback. Either way, I win."
---
The trigger list includes very broad, high-frequency phrases such as "grow my business," "advertising," and "content marketing," which can cause the skill to activate for many generic business queries outside the book’s intended scope. Unintended invocation can override more appropriate skills or inject irrelevant guidance, creating prompt-routing integrity issues and increasing the chance that users receive mismatched advice.
The trigger list contains very broad, high-frequency phrases such as "grow my business," "advertising," and "content marketing," which can cause the skill to activate for many ordinary business queries that are not specifically asking for this book-based skill. Overbroad activation can hijack routing, suppress more appropriate skills, and increase the chance that users receive mismatched sales/marketing guidance without clear intent.
The skill explicitly instructs users to contact strangers who have not given permission and frames success as a volume game, but it provides no warning about consent, privacy laws, anti-spam rules, or platform policies. In a business-advice skill, this can normalize behavior that leads users to send unsolicited outreach at scale, increasing risk of spam, policy violations, account suspension, or unlawful processing of personal data.
Line L08 states that the writing is intentionally kept at a 5th grade reading level and emphasizes short, simplified language as a requirement. This imposes a language/style constraint in natural language without offering the user any choice or opt-in.
No suspicious patterns detected.