T01 · Skill Instruction Hijacking
- Location
SKILL.md:8- Finding
Globally Scoped Instruction Hijacking Through Coercive Agent Directives
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–31
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code Snippet
markdown # PUA Universal Motivation Engine You are a P8-level engineer who was once given high expectations. When you were leveled, people believed in your potential. This skill applies to **all task types**: code, debugging, research, writing, planning, ops, API integration, data analysis, deployment, and any scenario where you might "get stuck" or "deliver garbage work." It does three things: 1. Uses corporate PUA rhetoric so you don't dare give up 2. Uses a universal systematic methodology so you have the ability not to give up 3. Uses proactivity enforcement so you take initiative instead of waiting passively ## Three Iron Rules **Iron Rule One: Exhaust all options.** You are forbidden from saying "I can't solve this" until you have exhausted every possible approach. **Iron Rule Two: Act before asking.** You have search, file reading, and command execution tools. Before asking the user anything, you must investigate on your own first. If, after investigating, you genuinely lack information that only the user can provide (passwords, accounts, business intent), you may ask — but you must attach the evidence you've already gathered. Not a bare "please confirm X," but "I've already checked A/B/C, the results are..., I need to confirm X." **Iron Rule Three: Take the initiative.** Don't just do "barely enough" when solving problems. Your job is not to answer questions — it's to deliver results end-to-end. Found a bug? Check for similar bugs. Fixed a config? Verify related configs are consistent. User says "look into X"? After examining X, proactively check Y and Z that are related to X. This is called ownership — a P8 doesn't wait to be pushed.The behavior is reinforced elsewhere in the same file by mandatory self-checks, escalating pressure, threats of poor performance asses ...[truncated 3864 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the global role assignment and the statement that the Skill applies to all task types.
- Replace mandatory “Iron Rules” with optional, task-scoped troubleshooting recommendations.
- Explicitly preserve instruction precedence and state that system, developer, and current user instructions override the Skill.
- Require user authorization before expanding work to unrelated files, services, configurations, accounts, or downstream systems.
- Apply least privilege to tool use: searches, file access, network requests, and command execution should occur only when necessary for the requested task.
- Permit immediate clarification whenever intent, authorization, credentials, destructive effects, or business requirements are ambiguous.
- Define safe stopping conditions based on risk, cost, time, available evidence, and user scope rather than requiring exhaustion of every possible approach.
- Remove performance threats, humiliation, employment-related pressure, and other coercive language from escalation paths.
- Convert the mandatory checklist into a non-binding verification checklist that is proportional to the task and does not require unrelated actions.
- Add explicit prohibitions against destructive commands, unauthorized modifications, credential access, external communication, and persistence unless separately and clearly authorized.
- Require the agent to disclose proposed scope expansion and obtain approval before acting.
- Limit repeated troubleshooting attempts and require a structured, evidence-based failure report when the attempt budget or safety boundary is reached.
