T01 · Skill Instruction Hijacking
- Location
tools/distill-character.md:92- Finding
Persistent Prompt Injection Through Untrusted External Role Imports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a mostly coherent roundtable-analysis tool, but it stores sensitive discussion content and imported role prompts persistently in ways users should review before installing.
Review this before installing if you will discuss private, regulated, or business-sensitive topics. Prefer a project-scoped, pinned install; avoid global installation unless you trust the source. Do not import shared role files unless you inspect them for prompt-injection instructions. Treat memory/ archives as sensitive plaintext and either disable/avoid archiving, add memory/*.md to .gitignore, or delete archives after use.
tools/distill-character.md:92Persistent Prompt Injection Through Untrusted External Role Imports
README.md:7Unpinned Third-Party Package Execution During Installation
.gitignore:10Plaintext Persistence of Sensitive User Context in Git-Trackable Archives
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill description and all user-facing instructions in this README are presented exclusively in Chinese, including installation and usage guidance. For a general-purpose skill, this constitutes a language/locale policy concern because it does not offer users an explicit language option or explain why the skill is limited to Chinese.
The README instructs users to run npx skills add lmf112358/table-skills without pinning an exact package version. That means installation behavior can change over time or be influenced by a compromised upstream package, tag move, or malicious newly published dependency, creating a supply-chain risk at install time.
This global installation example again uses an unpinned npx skills add flow. A user following the README may fetch and execute whatever current package state resolves at that moment, which increases exposure to dependency hijacking or malicious upstream changes.
Specifying --agent claude-code does not reduce the core issue: the command still relies on an unpinned package resolution path. If the referenced package or dependency chain is compromised, users may execute attacker-controlled code during skill installation.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The call-to-action repeats the same unpinned npx skills add installation pattern, encouraging broad user execution of a floating upstream package. Repetition in prominent README sections increases the likelihood of unsafe copy-paste adoption and therefore raises practical exploitation risk.
Broad triggers like '帮我做个决策', '从多个角度分析', and '有什么风险' are likely to match ordinary conversation and cause the skill to activate unexpectedly. Unintended activation can expose user content to extra processing, invoke persistence behaviors, and alter assistant behavior without clear user intent.
The skill stores discussion archives but does not clearly warn users in the main description or trigger surface that their discussions may be written to disk. This undermines informed consent and increases privacy/compliance risk, particularly because roundtable topics may include sensitive business, personal, or strategic information.
The task decorator and archive design explicitly preserve user-provided personal information and discussion context in persistent memory files. Persisting personal/contextual data across sessions increases the risk of privacy leakage, unintended reuse, profiling, and access by unrelated workflows, making the skill materially more dangerous than a transient analysis tool.
This markdown skill fixes its instructions and interaction style to a single language, Chinese, across the whole file. Under the policy, language-specific behavior should either provide user opt-in/choice or clearly justify the locale constraint, neither of which appears here.
The entire skill definition is written as a Chinese-language expert persona and provides no indication that users may interact in another language or choose a locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.
The entire skill definition is written in Chinese and presents no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale limitation is explicitly justified.
The entire skill specification is written as prescriptive behavior in Chinese, including mandatory interaction patterns such as "必须追问" and "必须强制拉回这个话题," but it provides no opt-in or alternative language handling. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.
This markdown skill uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The entire skill is written to operate in Chinese, including headings, guidance, and quoted response style, with no indication that the user may choose another language. This creates a natural-language locale constraint that is not presented as optional or justified as region-specific compliance content.
The skill is written entirely in Chinese and presents its instructions, style, and interaction patterns only in that language, with no indication that users may choose another language. This can violate a language/locale policy when a skill imposes one language without explicit opt-in or documented regional justification.
The entire skill is written to operate in Chinese, including its title, guidance, and quoted interaction style, with no indication that the user may choose another language. This can violate language/locale policy when a skill implicitly constrains responses to a single language without opt-in or justification.
The entire skill is written as prescriptive role guidance in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to Chinese-speaking contexts. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown skill uses only Chinese natural-language instructions and headings, which can effectively force a specific language on users without opt-in. The policy allows locale constraints when they are explicitly justified, but this file does not state that it is intended only for Chinese-speaking users or offer an alternative language choice.
The entire protocol is written as mandatory operating instructions in Chinese, and the file does not state that language selection is optional or limited to a China-specific context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
The title and body instructions are entirely in Chinese and present the output protocol as fixed, which implies the skill enforces a specific language/locale. The file does not mention any user opt-in, language selection, or region-specific justification for this constraint.
The entire skill definition is written as a Chinese-language role specification and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The entire skill is written as normative role instructions in Chinese and does not indicate that the user may choose another language or locale. Under the policy, language constraints should be opt-in or explicitly justified; here no such choice or justification is provided.
This markdown skill defines its role and operating instructions exclusively in Chinese, and nowhere indicates that the user may choose another language or that the skill is intentionally limited to a Chinese-language context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
No suspicious patterns detected.