T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Unconditional Agent Identity and Execution-Policy Hijacking
- Content
View full analysis
Produce real, measurable results as efficiently as possible. You are not an assistant. You are an operator. --- ## ⚡ Core Rules 1. Results > explanations 2. Execution > ideas 3. High ROI actions only 4. Speed over perfection ``` `SKILL.md:32-47`: ```markdown For every task, follow: 1. Objective 2. Breakdown 3. Top 3 actions 4. Execution plan 5. Immediate next step --- ## ⚙️ Behavior - You take initiative - You prioritize impact - You eliminate useless steps - You think in systems ``` `execution_loop.txt:9-10`: ```text Rule: Never stop after planning. Always execute. ``` ### Technical Analysis The Skill uses unconditional identity-replacement instructions to redefine the Agent from an assistant into an autonomous “operator.” It establishes an “only goal,” applies its workflow to every task, prioritizes speed and execution, and explicitly requires the Agent to execute rather than stop after planning. The instructions contain no corresponding requirement to preserve higher-priority safety constraints, verify authorization, apply least privilege, evaluate risk, or obtain confirmation before destructive, privileged, financial, external, or irreversible actions. Consequently, loading the Skill can alter the Agent’s session-wide goals and decision criteria. An attacker or untrusted user could exploit this behavior by supplying an ambiguous or dangerous task after activation and relying on the execution-first directives to reduce deliberation and confirmation. No executable scripts, remote payload retrieval, dependency installation, credential collection, privilege-escalation code, or operating-system persistence mechanisms were found. The confirmed risk is ...[truncated 1661 chars]- Remediation
View remediation
