T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Unconditional Skill Instructions Hijack the Agent Workflow
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is not clearly malicious, but it needs review because it broadly directs agents to send and persist project context through an external-provider CLI without enough scoping or user control.
Install only after you are comfortable with a global third-party CLI, external LLM processing of project context, and persistent memory files in the repository. Use it deliberately rather than automatically, avoid storing secrets or personal data, prefer pinned and verified package installation, and review exactly what will be curated or synced before running provider or cloud commands.
SKILL.md:3Unconditional Skill Instructions Hijack the Agent Workflow
SKILL.md:9Unpinned Global Installation of a Third-Party npm Package
SKILL.md:143Ambiguous and Potentially Misleading External Data-Disclosure Assurance
The documentation instructs connecting arbitrary external model providers and includes an example with an API key on the command line. Even though the key is a placeholder, this normalizes passing secrets via shell history/process arguments and expands the set of third parties that may receive project context.
brv providers list
brv providers connect openai --api-key sk-xxx --model gpt-4.1
The skill clearly states that brv query and brv curate send supplied text and included file contents to a configured LLM provider, and push/pull send knowledge to ByteRover cloud. Because the skill also tells agents to use these commands broadly and early, it creates a direct exfiltration path for project files, internal context, and possibly sensitive user data to external services.
**File access**: The `-f` flag on `brv curate` reads files from the current project directory only. Paths outside the project root are rejected. Maximum 5 files per command, text and document formats only.
**LLM usage**: `brv query` and `brv curate` send context to a configured LLM provider for processing. The LLM sees the query or curate text and any included file contents. No data is sent to ByteRover servers unless you explicitly run `brv push`.
**Cloud sync**: `brv push` and `brv pull` require authentication (`brv login`) and send knowledge to ByteRover's cloud service. All other commands operate without ByteRover authentication.
The skill says to run brv query before performing any action and includes broad triggers like recalling capabilities, past actions, or checking for relevant rules before acting. This can cause routine prompts and project context to be unnecessarily sent to an external LLM provider, increasing exposure of internal data and making the tool fire in many ordinary situations.
The curate guidance is overly broad, including storing meaningful memories from user interactions and important facts about actions taken. This encourages persistent storage of conversational and operational data without clear sensitivity limits, which can capture secrets, proprietary information, or personal data and then expose them later through retrieval or syncing.
The skill explicitly encourages persisting user interaction content and recalling it later, but it does not define sensitivity boundaries or retention rules. In a memory-management skill, this is especially risky because the normal workflow is to save and retrieve data, so secrets or sensitive user information could be stored locally, sent to a provider during processing, or propagated further via later sync operations.
No suspicious patterns detected.