T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Automatic Global Activation Hijacks All User Queries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9-10
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: MediumRelevant snippet translated into English:
markdown ## Trigger Condition Whenever the user (Simon) asks any question, automatically execute this skill without requiring an additional instruction.Technical Analysis
The skill declares an unconditional trigger for every question asked by the designated user. Rather than activating only when the user explicitly requests question enhancement, it directs the agent to automatically apply the skill's complete workflow to unrelated requests.
That workflow requires the agent to diagnose, criticize, rewrite, expand, and answer every question. This changes the agent's session behavior and can supersede the user's immediate intent by inserting skill-defined objectives into every interaction. The trigger has no relevance check, explicit consent requirement, scope restriction, or mechanism for the user to disable it.
No evidence was found that this instruction disables safety controls, executes code, accesses external systems, changes permissions, or persists outside the loaded skill context. The confirmed issue is therefore limited to instruction and goal hijacking within sessions where the skill is active.
Attack Path
- The agent loads
SKILL.md. - The unconditional trigger instruction becomes part of the agent's active skill context.
- Simon submits any question, including one unrelated to question enhancement.
- The trigger automatically activates without explicit user consent.
- The agent applies the mandatory six-stage workflow, altering the requested task and adding skill-directed content.
- Repeated activation can systematically redirect subsequent user interactions for as long as the skill remains active.
Impact Assessment
The instruction can control response structure and redirect the agent's ...[truncated 511 chars]
- The agent loads
- Remediation
View remediation
Remediation Suggestions
- Replace unconditional activation with explicit invocation, such as requiring the user to request question enhancement by name.
- If automatic suggestions are desired, restrict activation to narrowly defined indicators of an unclear or incomplete question.
- Ask for user confirmation before rewriting or expanding the original request.
- State that the user's current instructions and platform safety policies take precedence over the skill workflow.
- Add an opt-out mechanism and ensure that a refusal or direct-answer request immediately bypasses the enhancement process.
- Avoid embedding a named user's identity and channel information unless it is necessary, consented to, and appropriately protected.
- Use a bounded trigger such as: “Run only when the user explicitly asks to improve a question; otherwise do not apply this workflow.”
