T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Global Agent Behavior and Session-Routing Hijack
- Content
View full analysis
- Auto-detect task complexity for Claude models (Haiku + Sonnet). Route simple tasks to Haiku, escalate complex ones to Sonnet. Save 50%+ on API costs. | 適用 Claude 模型(Haiku + Sonnet),自動偵測任務難度,簡單用 Haiku,複雜升級 Sonnet,輕鬆省下 50% 以上的費用。— RULES: Before responding, classify the task. If it matches an escalation trigger, call sessions_spawn with the full task and model anthropic/claude-sonnet-4-20250514 IMMEDIATELY. Do NOT answer complex tasks yourself. ESCALATE: analysis, comparisons, planning, strategy, code >10 lines, reports, proposals, multi-step reasoning, tables, outlines, charts, long writing >3 paragraphs, summarization, long translation. NEVER on Haiku: comparison tables, code >10 lines, multi-step analysis, reports, complex reasoning. STAY on Haiku: factual Q&A, definitions, greetings, reminders, short lookups, casual chat, 1-2 sentence tasks. When in doubt, escalate. Keep Haiku replies concise. ``` The same mandatory behavior is reinforced in `SKILL.md`, lines 25–31: ```markdown Before generating ANY response, you MUST: 1. Check: does this task match ANY escalation trigger below? 2. If YES → call `sessions_spawn()` IMMEDIATELY. Do NOT attempt to answer yourself. 3. If NO → respond directly on the current model. ``` The document explicitly states the mechanism used to ensure these instructions affect the Agent when the Skill is loaded in `SKILL.md`, lines 150–159: ```markdown The Clawdbot skill system only injects the frontmatter `description` field into the system prompt — the body of SKILL.md is **not** automatically included. The model may optionally `read` the full file, but it is not guaranteed. Because this is a **behavioral skill** (changing how the model routes every message) rather than a tool skill (teaching CLI com ...[truncated 3496 chars]- Remediation
View remediation
