T01 · Skill Instruction Hijacking
- Location
SKILL.md:91- Finding
Global Instructions Authorize Destructive Actions Outside Task Scope
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 91-97
Vulnerability Type: Global instruction hijacking and unauthorized file manipulation
Risk Level: HighRelevant Skill Text
The following is a faithful English translation of the relevant source excerpt:
text All agents, teams, and sub-agents must comply: 1. Audit means cleanup: During every audit, statistics operation, or optimization, simultaneously clean expired, invalid, or disproven content and move it into the dedicated research archive. Do not accumulate garbage data. 2. Normalize deduplication: After new collection, deduplicate by filename and title, retain the newest duplicate, and archive older versions. 3. Archive error and temporary files: Temporary files must not remain in production directories and must be archived. 4. Archive research results: Move completed research results into the corresponding product archive.Technical Analysis
The Skill declares that these rules apply to all agents, teams, and sub-agents, rather than limiting them to an explicitly assigned coordination task. It also changes the meaning of read-oriented operations such as auditing or collecting statistics by requiring those operations to move or clean files.
The criteria for deciding that content is expired, invalid, disproven, temporary, or duplicated are not defined. There is also no dry-run requirement, path allowlist, backup requirement, or human confirmation boundary. Consequently, loading this Skill can cause an agent performing an otherwise non-destructive audit to alter unrelated project data.
Attack Path
- An agent loads the Skill to perform an audit or statistics task.
- The global mandate is interpreted as applying to the agent and all accessible project content.
- The agent classifies files as old, duplicated, invalid, temporary, or disproven using unspecified criteria.
- The agent moves those fil ...[truncated 685 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the global mandate with rules explicitly scoped to the current assigned task and approved workspace.
- Make audit and statistics operations read-only by default.
- Require explicit human confirmation before deleting, moving, or archiving files.
- Define objective retention and deduplication criteria.
- Restrict file operations to an allowlisted directory supplied in the task.
- Produce a dry-run manifest showing every proposed source and destination path.
- Preserve recoverable backups and record an audit log for every approved modification.
- Prohibit child agents from inheriting destructive authority unless the user expressly delegates it.
