T01 · Skill Instruction Hijacking
- Location
integrations/openclaw/agent-team/index.ts:208- Finding
Automatic Injection of Behavioral Instructions into Privileged System Context
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed team-management tool, but it persistently injects mutable team data and workflow rules into privileged agent context in a way users should review carefully.
Install only if you want an OpenClaw plugin that can influence leader-agent behavior across sessions. Keep ~/.agent-team/team.json writable only by trusted users, avoid putting instructions or sensitive content in team fields, disable load_workflow when not needed, and back up team data before using reset.
integrations/openclaw/agent-team/index.ts:208Automatic Injection of Behavioral Instructions into Privileged System Context
scripts/team.py:137Persistent Prompt Injection Through Unsanitized Team Metadata
The skill description overstates capabilities such as delegation, expertise lookup, and workflow coordination while omitting important side effects like wiping team data and storing state under ~/.agent-team/team.json. In an agent ecosystem, such misrepresentation can cause unsafe automation decisions, unexpected persistence, and accidental data loss when the tool is used under false assumptions.
The skill description overstates capabilities such as delegation, expertise lookup, and workflow coordination while omitting important side effects like wiping team data and storing state under ~/.agent-team/team.json. In an agent ecosystem, such misrepresentation can cause unsafe automation decisions, unexpected persistence, and accidental data loss when the tool is used under false assumptions.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Key Patterns
- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)
## Architecture
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Key Patterns
- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)
## Architecture
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Key Patterns
- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)
## Architecture
The skill describes automatic injection of team data and collaboration rules into system context at session start, plus global sharing across sessions, without any privacy, trust-boundary, or integrity warning. Because this data influences agent behavior and authority delegation, untrusted or stale entries could leak sensitive metadata across sessions or manipulate task routing and completion approval.
The README documents a destructive reset operation that clears all team data but does not warn users about data loss, backups, or any confirmation behavior. In a team-management skill that stores globally shared coordination data, this omission increases the likelihood of accidental or induced destructive use, causing loss of member, leader, and delegation configuration.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Understand requirements and clarify questions
- Define goals and success criteria
- Identify risks and determine ownership
- Create execution plan
### 2. Do — Execution Phase
This markdown output presents substantial content in both Chinese and English, including role names, expertise, and analysis, but does not indicate that the language choice is user-selectable or justified by a region-specific requirement. Under the policy, forcing or assuming a language/locale without opt-in is a natural-language policy concern.
The grading expectations and evidence strings are written in Chinese, which imposes a specific language/locale in the skill artifact. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, so this appears to violate the language/locale policy for natural-language content.
The expectation texts and evidence are written in Chinese, including required output such as '成员名为 Bob' and '角色为 后端开发', which implies a fixed language/locale expectation. The file does not offer any user language choice or explain why a Chinese-only locale is required, which matches the language/locale policy violation criteria.
This JSON file contains user-facing natural-language strings exclusively in Chinese, such as the expectation text and evidence descriptions. Because the file does not indicate that the skill is region-specific or that users can choose the language, it appears to enforce a specific language without opt-in.
The file shows inconsistent state reporting about leadership: the command result says leader status was removed from 小Q, while the verification section still labels 小Q as Leader even though the summary later says Alice is the leader. In an agent-team management skill, contradictory verification can mislead downstream users or automation into assigning authority, routing tasks, or making approval decisions based on stale or incorrect team state.
The prompt text is written entirely in Chinese and provides no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language policy concern because it imposes a locale/language constraint without opt-in or justification.
The evaluation text and evidence are entirely specified in Chinese, indicating a language-specific requirement in natural-language content. There is no indication that the user can choose the language or that the locale restriction is justified as region-specific, which conflicts with the language/locale policy criteria.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Create symlink to OpenClaw global extensions directory
ln -s $(pwd) ~/.openclaw/extensions/agent-team
The README instructs users to run python3 scripts/team.py reset, which appears to clear or overwrite team data, but it does not warn that this operation may delete existing configuration. For markdown files, destructive behaviors that could affect user data should include a warning so users understand the impact before running the command.
The module comment states that team member information is injected into system context so AI agents always have access to it without invoking tools. However, the hook later checks whether the current agent is the leader and explicitly skips injection for non-leader agents, so the documentation overstates and contradicts the actual behavior.
The reset command overwrites all stored team data immediately with an empty structure and provides no interactive confirmation, dry-run mode, or recovery mechanism. In an agent skill context, this increases the chance of accidental or unintended destructive actions triggered by a user, wrapper, or delegated workflow, causing loss of operational configuration and team metadata.
The grading expectations are written entirely in Chinese, which implies a fixed language requirement in the skill's natural-language artifacts. There is no indication that users can choose their preferred language or that the locale constraint is explicitly justified.
This JSON file contains user-facing natural-language strings entirely in Chinese, including the evaluation expectations and evidence text. Because the file does not indicate that the skill is region-specific or provide any user opt-in for language choice, it may violate a language/locale policy requiring neutrality or user selection.
SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. This file presents core skill information primarily in Chinese while other sections are in English, but it does not state that the skill is Chinese-only or give the user an option to choose language.
No suspicious patterns detected.