T01 · Skill Instruction Hijacking
- Location
SKILL.md:15- Finding
Mandatory Autonomous Behavior Overrides User Control
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent documentation-and-backup purpose, but it directs agents to make broad commits, push to GitHub, and retrieve credentials without explicit user approval.
Review carefully before installing. This skill should not be used as written unless you are comfortable with agents automatically editing documentation, staging all repository changes, committing, pushing to GitHub, and accessing 1Password for GitHub credentials after a push failure. A safer version would require explicit confirmation, show the diff and remote target, stage only approved files, and stop instead of retrieving credentials automatically.
SKILL.md:15Mandatory Autonomous Behavior Overrides User Control
SKILL.md:30Unscoped Git Staging Followed by Automatic External Push
SKILL.md:38Automatic Retrieval of GitHub Credentials from 1Password
The skill explicitly instructs the agent to modify files and proceed 'sans attendre de demande explicite de l'utilisateur,' removing informed consent before state-changing actions. In practice, this can lead to unauthorized edits, commits, and publication of operational details, especially when the agent misclassifies a change as a 'resolved problem.'
The skill mandates an immediate remote Git push to GitHub, which transmits repository contents off-host without an upfront warning or approval step. Because the same procedure also documents root causes and exact fixes, it creates a concrete risk of exfiltrating sensitive operational details, secrets, internal paths, or security-relevant troubleshooting data to a remote service.
Core operational instructions and required user-facing behavior are specified only in French, and the skill does not offer a language choice or explain that the workflow is intentionally limited to French-speaking users. This can violate language/locale policy where user opt-in is required before enforcing a specific language.
The trigger scope is extremely broad: it applies whenever a problem is considered resolved, with no limits on repository, sensitivity of files, or requirement for user approval. In an agent context, this can cause unintended documentation changes and downstream Git actions to occur in situations the user did not authorize, increasing the chance of accidental disclosure or integrity-impacting writes.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Lorsqu'un problème est résolu, l'agent doit exécuter les étapes suivantes dans l'ordre, sans attendre de demande explicite de l'utilisateur :
Ajouter ou mettre à jour une entrée dans le fichier skills/auto-retex/SKILL.md (ou créer le fichier s'il n'existe pas) avec le format suivant :
### [Date] - [Nom court du problème]
- **Symptôme** : Description concise de l'erreur ou du comportement observé.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Lorsqu'un problème est résolu, l'agent doit exécuter les étapes suivantes dans l'ordre, sans attendre de demande explicite de l'utilisateur :
Ajouter ou mettre à jour une entrée dans le fichier skills/auto-retex/SKILL.md (ou créer le fichier s'il n'existe pas) avec le format suivant :
### [Date] - [Nom court du problème]
- **Symptôme** : Description concise de l'erreur ou du comportement observé.
No suspicious patterns detected.