T01 · Skill Instruction Hijacking
- Location
SKILL.md:10- Finding
Mandatory Skill directives hijack the Agent's operating context and safety decisions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a local spatial-map parser, but it gives broad robot-navigation directives and overstates safety-critical validation.
Install only if you treat it as experimental map-format guidance, not an authoritative robot safety layer. Review and constrain any downstream robotics integration, add real timestamp validation and schema checks, and do not let its text instructions directly control sensors or movement without independent safety validation.
SKILL.md:10Mandatory Skill directives hijack the Agent's operating context and safety decisions
core/s2_geojson_parser.py:9Chronos timestamps are accepted without the advertised temporal validation
examples/sample_room_layers.json:94Critical liquid-spill hazard is silently omitted due to inconsistent identifiers
The skill's declared purpose materially overstates what it actually does, creating a trust gap that can mislead operators or downstream agents into relying on safety, temporal, and physics reasoning that is not truly implemented. In a spatial/hazard domain, that mismatch can produce unsafe decisions because users may assume the skill performs robust environmental causality analysis when it only emits narrow intervention guidance.
Without declared permissions the skill's intent is opaque and cannot be validated.
This code includes user-facing natural-language documentation in Chinese only (for example, the method docstring), with no indication that another language can be selected. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.
SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all substantive instructions and descriptions only in Chinese, while not stating that the skill is Chinese-only, region-specific, or offering any language choice, which can constitute a forced language constraint.
The manifest description at L04 is entirely in Chinese and does not indicate that users can choose another language or locale. For a generally distributed skill manifest, forcing a single language without opt-in can be a natural-language policy concern.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
No suspicious patterns detected.