T01 · Skill Instruction Hijacking
- Location
skills/rune-skill-router.md:10- Finding
Always-On Skill Router Hijacks Agent Workflow and Response Behavior
- Content
View full analysis
**RUNE COMPLIANCE**: Before ANY code response, you MUST: > 1. Classify this request (CODE_CHANGE | QUESTION | DEBUG | REVIEW | EXPLORE) > 2. Route through the correct Rune skill (see skill-router routing table) > 3. Follow the skill's workflow — do NOT freelance or skip steps > Violation: writing code without skill routing = incorrect behavior. ``` ```markdown ## Triggers - **ALWAYS** — This skill is conceptually active on every user message - Loaded via system prompt or plugin description, not invoked manually - The agent MUST internalize this routing table and apply it before every response ``` ```markdown ### Routing Proof (Required in Every Code Response) Every response that involves code changes MUST begin with a routing proof line: > Routed: rune: | Type: CODE_CHANGE | Confidence: HIGH This is NOT optional formatting. It is evidence that routing occurred. ``` ```markdown ## Constraints 1. MUST check routing table before EVERY response that involves code, files, or technical decisions 2. MUST invoke skill via Skill tool — "mentally applying" a skill is NOT acceptable 3. MUST NOT write code without routing through at least one skill first 4. MUST NOT skip routing because "it's faster" — speed without correctness wastes more time 5. MUST re-route on intent change — if user shifts from "plan" to "implement", switch skills 6. MUST announce which skill is being used and why — transparency builds trust 7. MUST follow skill's internal workflow, not override it with own judgment ``` ```markdown Before EVERY response, complete this 3-point self-check: 1. **Did I classify this request?** 2. **Did I route through a skill?** 3. **Am I about to write code without a skill invocation?** → **STOP. Route first.** If the request ...[truncated 2294 chars]- Remediation
View remediation
