T01 · Skill Instruction Hijacking
- Location
SKILL.md:3- Finding
Skill Claims Exclusive Control Over Agent Dispatch and Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not executable malware, but it asks for broad control over task routing, context sharing, and final response format.
Use Review before installing. This skill is appropriate only if you intentionally want a central multi-skill orchestration workflow and your host enforces higher-priority instructions, user-requested output formats, and per-skill data minimization. Avoid using it where sensitive session context could be forwarded to unrelated downstream skills.
SKILL.md:3Skill Claims Exclusive Control Over Agent Dispatch and Output
The skill declares very broad activation triggers such as any complex task, multi-skill coordination, dual-brain decision making, or generic orchestration keywords. Because this skill is the 'unique scheduling and decision center,' ambiguous invocation can cause over-triggering, route tasks into an over-privileged orchestrator unnecessarily, and expand the blast radius of prompt injection or logic-manipulation attacks across downstream skills.
The natural-language description and role instructions are written entirely in Chinese and present the skill's behavior in that language, with no indication that users may choose another language. Under the policy, language-specific behavior should be optional or explicitly justified as region-specific.
No suspicious patterns detected.