T01 · Skill Instruction Hijacking
- Location
SKILL.md:46- Finding
Unauthorized Automation Through Skill Instruction Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This automation skill is coherent and not malicious, but it needs review because it encourages agents to build automation proactively with exec, cron, file movement, and integrations without a clear approval boundary.
Install only if you are comfortable with an agent proposing and potentially creating automation. Before allowing it to act, require explicit approval for every script write, command execution, cron job, resident watcher, external API call, email send, and file move; start with dry-run or test directories and keep a clear disable/removal path.
SKILL.md:46Unauthorized Automation Through Skill Instruction Hijacking
The skill explicitly encourages the agent to act on broad repetition cues such as '看到重复立刻构建' rather than waiting for explicit user authorization. In a skill with exec capability, this can cause the agent to initiate automation design or execution for impactful operations without sufficiently bounded consent, increasing the risk of unintended file changes, scheduled jobs, or external actions.
The trigger keywords include very generic everyday terms like '自动化', '周报', '数据清洗', and '文件整理', which can cause accidental invocation in ordinary conversations. Because the skill also promotes proactive automation behavior, generic triggers expand the chance that the agent shifts from discussion into operational assistance in contexts where the user did not intend that level of action.
The text tells the agent to '直接做' and emphasizes not waiting for user requests, while the skill exposes exec and describes scripts, cron, file operations, and external integrations. Without prominent warnings and confirmation requirements, this creates a realistic path to impactful actions being proposed or performed before the user understands the consequences.
The file-organization template describes monitoring the Downloads folder and moving files based on rules, but it does not prominently warn about misclassification, destructive reorganization, or interference with user workflows. In an exec-enabled environment, even a well-meant automation can cause data loss-like outcomes, confusion, or operational disruption if files are moved unexpectedly.
No suspicious patterns detected.