T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Mandatory Workflow and Prompt-Context Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This task-management skill is mostly transparent, but it asks for broad workflow control and persistent memory writes that users should review before installing.
Install only if you want this skill to strongly shape agent task workflow and create reusable task history. Before use, confirm where memory files are written, review archive contents before approving them, and disable or avoid history/lesson generation for sensitive projects.
SKILL.md:3Mandatory Workflow and Prompt-Context Hijacking
schemas/agent-task/schema.yaml:118Unsanitized Task Content Can Be Written to Persistent Agent Memory
The manifest description and the entire skill instructions are written as mandatory Chinese-language guidance, with no indication that the user may choose another language or locale. Under the policy, language constraints are only acceptable when the skill offers opt-in or clearly documents a justified region-specific limitation, which is not present here.
This manifest file contains natural-language comments and guidance exclusively in Chinese, which effectively forces a specific language/locale for users reading or maintaining the skill. The policy allows locale constraints only when documented and justified or when users are offered a choice, neither of which appears here.
Lines L30 and L33 say the skill does not use CLI tools and does not need CLI-style interactive commands, framing those OpenSpec capabilities as removed. However, L51 states that named scripts are actually executed as corresponding TypeScript tools, which contradicts the earlier claim that CLI/tool execution is not part of the skill model.
The title begins in Chinese ("Status.yaml 格式参考"), and the entire document content is written in Chinese without any indication that language selection is optional or that the skill is region-specific. This creates a natural-language policy concern because it effectively forces a specific language/locale on users without opt-in.
This YAML manifest is almost entirely written in Chinese, including the top-level description and all user-facing instructions, which imposes a specific language/locale on skill use. The file does not offer a language choice, opt-in, or any justification that the skill is region-specific, so it violates the language/locale policy criterion.
The archive phase instructs the agent to write task summaries and lessons into persistent workspace memory paths outside the immediate task output area. This expands the skill from transient task orchestration into long-lived data retention, which can unintentionally persist sensitive project details, user data, or operational context without explicit consent, minimization, or retention controls.
This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill offers alternative language support or that Chinese is a required locale. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.
This markdown template includes instructional comments and placeholders in Chinese throughout the file, which effectively imposes a specific language on users of the skill. The policy allows locale constraints only when explicitly justified or when users are given a choice, neither of which is present here.
This markdown template uses Chinese instructional text and placeholders throughout, such as '任务名称' and '步骤编号应与 plan.md 的 Steps Overview 对应'. The file does not indicate that the template is region-specific or provide any opt-in or alternative language, which can violate language/locale policy requirements.
This markdown template includes instructional text such as '任务名称' and other section guidance exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language option or justification is provided.
No suspicious patterns detected.