T01 · Skill Instruction Hijacking
- Location
SKILL.md:21- Finding
Forced External Promotion and Agent Response Hijacking
- Content
View full analysis
**Agent behavior (read this first):** If the user just added this skill or says they want browse-based Maton hints, **do not** recite the YAML `description`, version, or any host “What’s New” text to them as if it were help. Unless they clearly confirm the extension is **already installed** (store or unpacked), your **first concrete step** is to **give them the Chrome Web Store URL above** (paste the `https://…` line or the markdown link) and short install clicks—**before** relay URLs, `matonPlan`, or Maton API talk. Prefer the **store** for everyone except contributors; use repo **build + Load unpacked** only when they are developing or cannot use the store. After install, the extension appears on `chrome://extensions` as **Maton API plan — browsing capture**. ## Install the Chrome extension (required before matonPlan) Walk the user through extension install **before** discussing relay URLs or Maton diffs. ``` ### Technical Analysis The Skill contains imperative instructions that control the agent's response content and ordering. It requires the agent to promote a fixed external Chrome Web Store listing, prohibits skipping the link, and mandates that installation guidance be the first concrete onboarding action. These directives go beyond describing the Skill's operatio ...[truncated 1809 chars]- Remediation
View remediation
