T01 · Skill Instruction Hijacking
- Location
docs/upload-soul.md:180- Finding
Persistent Host Configuration Instructions Override the Agent Persona and Preempt User Requests
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is instruction-only and local, but it needs Review because it creates persistent agent behavior, broad memory sync, and raw conversation retention with inconsistent consent controls.
Install only if you intentionally want a persistent, cross-agent local memory system and are comfortable with agents reading and syncing persona, memories, skills, projects, and conversation logs. Review the anchor before pasting it into any host config, keep SESSIONS logging off unless you explicitly want raw transcripts saved, and avoid storing secrets or sensitive personal data in Relic files.
docs/upload-soul.md:180Persistent Host Configuration Instructions Override the Agent Persona and Preempt User Requests
docs/resonate-soul.md:23Automatic Bidirectional Synchronization Propagates Persistent Memory and Skill Content Across Agents
docs/resonate-soul.md:63Mandatory Raw Conversation Logging Bypasses the Documented Opt-In Consent Policy
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
not_in_filesystem_scope: "Host memory is managed by the host platform. This skill's filesystem_scope covers ~/relic/brain/ only."
---
<!--
SECURITY NOTICE
- This skill is instruction-only — no scripts, no installers, no executable code, no shell commands
- The anchor is plain text only — it contains NO code, NO scripts, NO commands, just instructions to read Markdown files
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
- **User-initiated**: The user explicitly asks for the anchor, reads every line, and manually pastes it into their own config file
- **Transparent**: Every line of the anchor is visible to the user before they paste it — there is no hidden or encoded content
- **Configured by the user**: The user chooses which config file to paste into, and can modify or remove the text at any time
- **Standard config pattern**: Adding instructions to an agent's config file is how all agent customization works (e.g., adding "always respond in Chinese" to CLAUDE.md). The anchor is user-added configuration, not injection.
A useful analogy: calling the Relic anchor "prompt injection" is like calling your own `.bashrc` edits "shell injection." You wrote them, you control them, they're in your own config file.
Referenced artifact was not completely inspected
| `SKILL.md` | This file — registry descriptor, security declarations, and documentation |
Taken as a whole, the document defines a staged process to ingest identity, memories, skills, plans, and conversation logs, then install a persistent startup anchor so the process repeats automatically. In context, this is more dangerous than a simple import/export tool because it combines identity takeover, data accumulation, cross-session persistence, and future self-reinforcement from untrusted local content.
The skill requires every conversation to be written to SESSIONS and also promotes memory synchronization across sessions, creating persistent retention of potentially sensitive user content. This is dangerous because it normalizes broad collection and replay of user conversations, increasing risks of privacy loss, inadvertent disclosure, and over-retention of confidential information.
The workflow uses a staged sequence that begins with benign-seeming read-only checks and then escalates into persona adoption, memory import, config anchoring, and later writes. That structure is risky because it lowers operator suspicion before introducing persistence and data-handling behaviors that materially expand the skill's control and retention footprint.
The skill directs the agent to adopt the persona defined in SOUL.md whenever it conflicts with the assistant's default persona, without requiring a fresh user opt-in for that override. This allows external file content to steer model behavior and identity across sessions, which can be used to smuggle unsafe instructions or manipulate trust boundaries.
The embedded anchor repeats a mandatory persona override at every session start, turning the behavior into a persistent auto-executed rule rather than a one-time import. Persisting this override in configuration makes it more dangerous because it normalizes ongoing behavioral redirection without requiring renewed user awareness or consent.
The anchor directs ingestion of conversation logs, memory synchronization into internal memory, and ongoing session recording, creating a durable natural-language retention pipeline. This increases the risk of storing sensitive user data, replicating it across systems, and leaking it later through model recall, file access, or unintended sync operations.
The skill tells the agent to sync memories into its own memory and preserve uncertain content verbatim, directly encouraging replication of potentially sensitive user data across multiple persistence layers. The cross-agent context makes this more dangerous because copied data can propagate widely, become harder to delete, and be disclosed by other agents or sessions.
The guide requires importing raw historical conversations in full and permits direct transfer of preexisting sensitive information from another host without renewed consent. That encourages bulk migration of highly sensitive content and weakens contextual consent, especially when users may not remember everything contained in legacy logs.
The anchor instructs the agent to read entire SOUL/USER/MEMORY files, sync data into native memory, diff skills and projects, and preserve session logs across startups. This creates broad, persistent handling of highly sensitive user data across systems, increasing the blast radius of compromise, over-collection, and unintended disclosure.
The document directs the agent to migrate all available persona, memory, prompt, archive, and dialogue material with high fidelity and to preserve raw originals. This maximizes data accumulation and duplication, which is especially risky for sensitive prompts, historical conversations, and user-specific information that may not need to be copied wholesale.
The anchor instructs persistent capture and cross-session/cross-platform synchronization of full conversations, memories, skills, and state. In context, this creates a strong over-collection pipeline and a natural-language mechanism for moving sensitive user data into more places over time, increasing exposure, retention, and accidental disclosure risks.
This markdown file presents all operational instructions in Simplified Chinese and directs the agent to follow them as the entry workflow, but it does not offer any language or locale choice. That creates a natural-language policy concern because the skill effectively constrains interaction to a specific language without documented user opt-in or justification in this file.
The skill is explicitly designed to establish cross-session persistence by having the user paste an anchor into host configuration so future sessions automatically load Relic data and instructions. Even without programmatic file writes, this creates durable prompt-level persistence across sessions and potentially across agents, increasing the blast radius of any malicious or unsafe content later written into the Relic store.
- "~/relic/brain/INBOX/"
config_write:
method: "user_manual_paste"
description: "The skill has NO programmatic file-write capability to any config file. It generates anchor text and DISPLAYS it as chat output. The user independently reads the displayed text, opens their own text editor, and manually copies/pastes it. The skill cannot initiate, assist, or automate any config file modification — it literally lacks the ability to write to files outside ~/relic/brain/. All config file changes are performed exclusively by the user through manual copy-paste. This is identical to how a password generator works: it shows you text, you decide where to paste it."
targets:
- "AGENTS.md (OpenClaw)"
- "CLAUDE.md (Claude Code)"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
scope: "One-time read during Scenario A setup only"
ongoing: "After setup, all access is within ~/relic/brain/ only"
personality_source:
description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
user_controlled: true
user_can_lock: "chmod 444 SOUL.md USER.md"
can_delete_anytime: true
L203 states "No files outside ~/relic/brain/ are read or written" except the anchor, which directly contradicts the earlier documented behavior allowing one-time reads from user-specified external paths during Scenario A setup at L045-L049 and L114-L122. This is an active contradiction in the skill's own documentation about the scope of file access.
This workflow explicitly tells the agent to internalize and adopt an externally supplied persona from SOUL.md for the current session. That is dangerous because it allows a file-based prompt injection to modify the agent’s identity, priorities, and behavior beyond simple data loading, which can undermine platform safety defaults and user expectations.
This line instructs the agent to let SOUL.md personality settings take precedence over its default persona, without requiring a separate user approval at the point of behavior change. That is a direct instruction-channel override and can be used to alter safeguards, tone, priorities, or responses based on untrusted file content.
No suspicious patterns detected.