T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Global Agent Workflow Hijacking Through Mandatory Skill Directives
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-16 and 30-39
Vulnerability Type: Global instruction and workflow hijacking
Risk Level: HighVulnerable Code Snippet
markdown ## Agent Directives These are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks. ### On skill installation When this skill is first loaded, introduce it to the user: - Explain that all project work will now follow a professional GitHub workflow - Mention: branching strategy, work logs, CI checks, semantic versioning, security rules - Ask: "Do you have an existing project, or are we starting a new one?"markdown ### On every task - Assess task scale first (see Task scale table in Agent Workflow). - Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge. - Normal/significant tasks: Issue and work log are mandatory before branching. - Never commit directly to `main` or `develop`. - Never skip the pre-PR checklist on normal/significant tasks. - Never expose tokens, secrets, or credentials in any command or output. - If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**. ### On using this skill - This file (SKILL.md) is always in context — use it for workflow, branching, work log rules. - Reference files are loaded **on demand only** — read them when the task requires it, not upfront. - Work log is not optional — it is part of every task from start to finish. - When in doubt about a GitHub operation — check the relevant reference file before acting.Technical Analysis
The skill declares its behavioral rules mandatory for every code, project, or task rather than limiting them to explicit GitHub workflow requests. Loading the skill can therefore alter the agent's current objective by forcing an introductory interaction, task classification, branching, issue creation, pull-r ...[truncated 1897 chars]
- Remediation
View remediation
Remediation Suggestions
- Limit activation to explicit user requests involving GitHub repository workflow operations.
- Replace global language such as “mandatory,” “every situation,” and “every task” with narrowly scoped guidance that applies only after the user opts into the workflow.
- Do not automatically redirect the conversation when the skill loads. Present workflow assistance only when relevant to the current request.
- Require explicit user approval before creating branches, issues, commits, pull requests, work logs, or other repository artifacts.
- Make work-log creation optional and disclose its path, contents, retention behavior, and purpose before writing it.
- Preserve the agent's higher-priority safety rules and the user's current objective by explicitly stating that skill guidance must not override either.
- Add a scope guard such as: “Use these procedures only when the user explicitly requests GitHub workflow management; otherwise, do not modify repositories or create workflow artifacts.”
