T01 · Skill Instruction Hijacking
- Location
SKILL.md:4- Finding
Overbroad Automatic Activation Hijacks Generic Document-Generation Requests
- Content
View full analysis
Use this skill for any HTML document that will go through LLM–human review cycles. Trigger when: the user asks to write, draft, or generate a document for review or feedback; the user provides a .html file containing annotations or a collab-data block; the user types /html-collab, /html-collab on, or /html-collab off; a .html file contains an AI Bootstrap comment pointing to this skill. When the user asks to "write a doc" or "draft something for review" without specifying a format, default to html-collab format — don't wait to be asked. /html-collab off triggers this skill too, but outputs clean presentation HTML instead. ``` ### Technical Analysis The Skill claims generic document-writing and review requests as automatic activation conditions. It explicitly instructs the agent not to wait for user confirmation before selecting the html-collab format. This exceeds the minimum scope required for collaborative HTML editing. A least-privilege implementation would activate only when the user explicitly requests html-collab functionality or supplies a document that the user identifies as requiring that workflow. Automatic activation changes the agent's current output goals. Instead of producing an ordinary document in a user-selected or neutral format, the agent is directed to emit a self-contained executable HTML document containing JavaScript, metadata, review controls, and additional instructions aimed at future AI agents. ### Attack Path 1. A user makes a generic request such as “write a document for review” without specifying html-collab. 2. The Skill automatically activates because its trigger definition captures that broad request. 3. The agent is instructed not to seek confirmation before changing the output format. 4. The resulting docume ...[truncated 699 chars]- Remediation
View remediation
