T01 · Skill Instruction Hijacking
- Location
SKILL.md:35- Finding
Overbroad Trigger Rules Can Hijack Skill Selection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent scheduling/reminder helper, but it asks agents to use broad scheduling authority and includes unsafe recovery/elevation guidance that users should review before installation.
Install only if you are comfortable with an agent creating and managing scheduled tasks. Before use, require explicit confirmation for creating, changing, or deleting jobs; avoid following the state-file deletion and administrator-running advice unless an administrator has reviewed the exact path, backup, and recovery plan.
SKILL.md:35Overbroad Trigger Rules Can Hijack Skill Selection
SKILL.md:123Persistent Timezone Writes Can Poison Future Scheduling State
SKILL.md:138Destructive Scheduler Recovery Can Delete Unrelated Tasks
SKILL.md:364Generic Administrator Execution Advice Violates Least Privilege
The activation criteria are broad enough to match common conversational words like '提醒', '定时', or '调度', making unintended invocation likely. Over-broad triggering increases the chance that the skill takes over unrelated tasks and applies scheduling behaviors or tool usage where the user did not want them.
The forced activation rule mandates priority invocation for ambiguous keywords and prescribes behavior changes such as banning act:wait in certain cases. This reduces agent discretion and can cause the skill to override safer or more appropriate workflows based on weak lexical matches.
The troubleshooting flow recommends deleting local state files without a prominent warning that this may destroy scheduled jobs and require manual reconstruction. In a tool-enabled agent environment, such instructions can directly lead to irreversible data loss from routine support interactions.
The skill branding, description, and examples are written as if the skill is inherently for Chinese-language and China-oriented messaging platforms, but there is no opt-in or alternative locale/language path. This can violate language/locale policy when a skill implicitly forces a specific language or regional workflow without user choice.
The skill instructs storing user timezone data in MEMORY.md without clear notice, consent, retention limits, or scope controls. Although timezone is not highly sensitive by itself, persistent storage of user attributes in shared memory can create privacy and context-leakage risks across future sessions or tasks.
The skill goes beyond reminder guidance and instructs operators to back up and delete local cron state files and restart the platform. In an agent context with Bash/Write/Edit tools, this can cause accidental destructive maintenance actions, loss of scheduled jobs, and unsafe normalization of direct state-file manipulation without guardrails or validation.
The FAQ introduces OS-level cron/crontab and @reboot guidance even though the skill says it only operates within the Agent platform. That mismatch can cause an agent or user to apply instructions to the host system, expanding scope from in-platform scheduling to system-level persistence and task execution.
The document presents conflicting execution models, describing both command-execution capability and pure Markdown guidance. This ambiguity can mislead an agent into taking more privileged actions than intended, especially when the skill advertises Bash access elsewhere.
Persisting timezone in shared memory creates a retention and cross-context privacy risk because user attributes may be reused beyond the immediate scheduling task. In isolation the sensitivity is low, but the pattern normalizes storing personal context without lifecycle controls.
No suspicious patterns detected.