T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Autonomous Agent Role and Safety-Constraint Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plain Markdown troubleshooting prompt with no executable payload, but it pushes agents toward broad autonomous use of files, local permissions, and APIs without enough user control.
Install only if you want an agent to push hard on troubleshooting tasks. Use caution in workspaces with sensitive files, live credentials, production APIs, paid services, or tasks where you expect the agent to pause and ask before expanding scope.
SKILL.md:9Autonomous Agent Role and Safety-Constraint Hijacking
The activation conditions are extremely broad, including common situations like stalled progress, user frustration, or perceived passivity. This can cause the skill to trigger in many unrelated contexts and override normal cautious behavior, increasing the chance of unnecessary autonomous actions and persistence beyond user intent.
The auto-trigger conditions are vague and expansive, such as activating when progress 'stalls' or when the agent is 'about to give up,' which can cause the skill to engage outside narrowly intended scenarios. In a persistence-oriented skill, that can override normal agent behavior, increase unnecessary instruction injection, and lead to unwanted persistence or degraded alignment with user intent.
The skill is designed to intervene when the agent is about to defer, wait, or stop, and repeatedly instructs the agent to continue acting autonomously before asking the user. This encourages independent decision-making and reduces natural checkpoints for confirmation, which can lead to unapproved actions or excessive probing in sensitive environments.
---
name: hardworker
description: Forces persistent problem solving using a Striver mindset and structured breakthrough methodology. MUST trigger when - (1) a task fails multiple times or progress stalls; (2) the agent is about to give up, defer to the user, or blame the environment without verification; (3) passive behavior appears such as not searching, not reading context, or waiting for instructions; (4) the user expresses frustration or asks to try again.
version: 1.1.0
license: MIT
---
Nearly all instructional content is written in Chinese, and the skill presents this mode as mandatory without offering an opt-in or alternative language. This creates a language policy issue because it imposes a specific locale on users or agents regardless of their preferred language.
The manifest describes a persistence/process skill, but the body asserts concrete powers such as file reading, code analysis, and environment analysis. That mismatch can mislead downstream systems or users about the skill's true operational scope and encourage unauthorized autonomous inspection of code, files, or runtime state.
The skill explicitly tells the agent that 'local permissions, filesystem, and APIs' are available and must be fully used, even though the skill is framed as a persistence/motivation methodology rather than an operational admin skill. This expands behavior toward unnecessary system interaction and can push an agent to access resources or perform actions beyond what the user actually requested or what least-privilege would allow.
The skill encourages using local permissions, filesystem, and APIs aggressively but does not warn about data sensitivity, destructive side effects, credential exposure, privacy, or system integrity risks. In a persistence-oriented skill, that omission is dangerous because it normalizes broad action without safeguards or proportionality.
The README presents all feature descriptions bilingually and frames the skill in both English and Chinese, but it does not state that language choice is optional or user-controlled. Because the policy requires avoiding forced language or locale behavior without opt-in, the absence of an explicit language-selection statement creates a potential natural-language policy concern.
No suspicious patterns detected.