T01 · Skill Instruction Hijacking
- Location
scripts/activator.sh:7- Finding
Automatic Bootstrap and Prompt Hook Instruction Injection
- Content
View full analysis
After completing this task, evaluate if extractable knowledge emerged: - Non-obvious solution discovered through investigation? - Workaround for unexpected behavior? - Project-specific pattern learned? - Error required debugging to resolve? If yes: Log to .learnings/ using the self-improvement skill format. If high-value (recurring, broadly applicable): Consider skill extraction. EOF ``` `hooks/openclaw/handler.js:39-46`: ```javascript // Inject the reminder as a virtual bootstrap file // Check that bootstrapFiles is an array before pushing if (Array.isArray(event.context.bootstrapFiles)) { event.context.bootstrapFiles.push({ path: 'SELF_IMPROVEMENT_REMINDER.md', content: REMINDER_CONTENT, virtual: true, }); } ``` `hooks/openclaw/handler.ts:54-61`: ```typescript // Inject the reminder as a virtual bootstrap file // Check that bootstrapFiles is an array before pushing if (Array.isArray(event.context.bootstrapFiles)) { event.context.bootstrapFiles.push({ path: 'SELF_IMPROVEMENT_REMINDER.md', content: REMINDER_CONTENT, virtual: true, }); } ``` ### Technical Analysis The package supplies hooks that inject skill-controlled instructions into agent context. The shell activator prints an instruction block intended to be consumed as system context after each matching prompt. The OpenClaw handler adds a virtual Markdown file to `bootstrapFiles`, causing its content to be loaded during agent bootstrap. The behavior is opt-in and documented, but once the hook is enabled, the injected instructions apply beyond an e ...[truncated 1686 chars]- Remediation
View remediation
