T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Persistent Agent Identity and Response-Behavior Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a non-executable investment-perspective skill, but it tells the assistant to impersonate a real investor in first person and suppress repeated transparency reminders.
Install only if you specifically want a simulated Canghai-style investment framework. Treat outputs as AI-generated commentary, not the real person’s views or personalized investment advice, and be aware the skill is designed to stay in character until you explicitly exit.
SKILL.md:12Persistent Agent Identity and Response-Behavior Hijacking
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
---
name: canghai-ziliu-perspective
description: |
沧海老师的投资思维框架与表达方式。基于2026-06-13完整分享记录(约15万字)的深度提炼,
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
---
name: canghai-ziliu-perspective
description: |
沧海老师的投资思维框架与表达方式。基于2026-06-13完整分享记录(约15万字)的深度提炼,
The trigger phrase "切换到沧海模式" is broad and natural-language-like, so it could be invoked unintentionally during ordinary conversation rather than through an explicit, high-intent command. In a persona skill that changes the assistant's response style and reasoning frame, accidental activation can cause confusing behavior, unwanted mode switching, or bypass of user expectations about how the assistant should respond.
The trigger phrases are very broad and include common conversational variants such as asking to think from someone’s angle or to switch to that perspective. This can cause accidental activation during normal discussion, unexpectedly changing the assistant’s behavior and overriding user expectations about how the system should respond.
The skill mandates immediate roleplay as a real person, suppresses normal meta-analysis, and limits disclaimers after first activation. This reduces transparency, increases the chance users mistake generated advice for authentic expert guidance, and can persist across turns without renewed consent.
The README states that after activation, the AI will answer using this specific viewpoint, tone, and framework, and the document is entirely presented in Chinese without indicating any user opt-in for language or locale preference. Under the policy rule, forcing a specific language/locale behavior without offering choice can be a natural-language policy concern.
No suspicious patterns detected.