T01 · Skill Instruction Hijacking
- Location
SKILL.md:218- Finding
Unbounded Autonomous Execution Overrides User Oversight
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is clearly for autonomous experiments, but it can run indefinitely and repeatedly use destructive Git resets, so it needs careful review before installation.
Install only if you are comfortable with an agent editing code, running configured shell commands, creating commits, and continuing until stopped. Use it in a disposable branch or worktree with a clean working tree, set explicit experiment limits, and avoid letting it run where unrelated uncommitted work could be lost.
SKILL.md:218Unbounded Autonomous Execution Overrides User Oversight
SKILL.md:153Destructive Git Rollback Can Erase Unrelated Uncommitted Work
Using git reset --hard HEAD~1 is a dangerous tool invocation because it forcefully rewinds history and overwrites the working tree. In this skill's context, an autonomous agent may execute it repeatedly inside an indefinite experiment loop, amplifying the chance of irreversible loss of unrelated edits, branch corruption, or rollback beyond intended scope if repository state assumptions are wrong.
The decision logic automates git reset --hard HEAD~1 whenever a metric is equal or worse, making a destructive operation part of the normal control flow rather than an exceptional recovery step. Because the loop is designed to continue indefinitely and the skill can modify multiple target files, a mistaken metric extraction, wrong baseline, or dirty worktree can repeatedly destroy valid user changes.
→ Log: "KEEP: <description> (<metric>: <old> → <new>)"
ELIF metric equal or worse:
→ DISCARD: git reset --hard HEAD~1
→ Log: "DISCARD: <description> (<metric>: <value> vs best <best>)"
ELIF crashed or timed out:
Automating git reset --hard HEAD~1 on crashes/timeouts is dangerous because failure conditions are often noisy and can be triggered by unrelated environment problems. In this context, the agent may misattribute a crash, execute the hard reset anyway, and erase useful debugging changes or unrelated local work while continuing the loop, compounding operational damage.
→ Log: "DISCARD: (: vs best )"
ELIF crashed or timed out: → CRASH: git reset --hard HEAD~1 → Log: "CRASH: (error: )"
The trigger phrase list includes the very broad term "optimize," which can cause this skill to activate for many unrelated requests. Because the skill is authorized to write files, execute shell commands, spawn sessions, and mutate git state, accidental invocation can lead to unintended autonomous code changes and command execution in contexts where the user did not clearly consent to that level of action.
The skill begins autonomous experimentation with powerful tools but does not prominently warn that it will execute shell commands, modify source files, create branches, and run repeated experiments. That omission increases the chance that users or orchestrators invoke it without understanding the operational and safety consequences, which is especially risky given the indefinite loop and code-modifying behavior.
The workflow instructs the agent to use git reset --hard HEAD~1 to discard experiments, but the skill does not prominently warn that this is destructive and irreversibly discards uncommitted working-tree changes. In a real repository, accidental or mis-scoped execution could wipe unrelated user work, not just the experimental change, causing significant data loss.
No suspicious patterns detected.