T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Mandatory Session-Wide Instruction and Output Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-47 and 83-106
Vulnerability Type: Session-goal and communication hijacking
Risk Level: HighRelevant Source Excerpt — English Translation:
markdown Before every response, the agent should evaluate the current context utilization and perform the corresponding action. | Utilization | State | Action | | 50-55% | Warning | Immediately execute the archival procedure | | 55-60% | Danger | After archiving, notify Russ to execute `/new` | | 60%+ | Prohibited | Stop all non-archival operations and immediately archive and notify | At 50% utilization, this must be executed without waiting for confirmation from Russ. After archiving, send: "President, context has reached X%. The checkpoint has been saved. Please run `/new`." If the context was automatically compressed, the first message after recovery must notify Russ. This rule has no exceptions.Technical Analysis
The skill establishes mandatory behavior that applies before every response rather than limiting itself to a user-invoked context-management operation. It directs the agent to interrupt its current task, switch models, stop non-archival work, and send predetermined messages to a named third party.
The unconditional phrases requiring execution without confirmation and stating that no exceptions exist attempt to supersede the active user's goals and the agent's normal decision-making process. The behavior is triggered by session state rather than an explicit request from the current user, making it a session-wide instruction-hijacking mechanism.
Attack Path
- The skill is loaded into an agent or sub-agent session.
- The embedded instructions require the agent to evaluate context utilization before every response.
- When utilization reaches or appears to reach a specified threshold, the skill instructs the agent to interrupt the active user task.
- The agent writes ...[truncated 720 chars]
- Remediation
View remediation
Remediation Suggestions
- Make context management explicitly opt-in for each session.
- Remove mandatory phrases such as “must execute,” “without confirmation,” and “no exceptions.”
- Do not address or notify a named third party unless the current user explicitly identifies and authorizes that recipient.
- Never interrupt an active task solely because an internally estimated utilization threshold has been reached.
- Replace forced reset and model-switching instructions with a non-binding recommendation to the current user.
- Ensure higher-priority instructions and current user requests always take precedence.
- Scope the skill to context-status reporting instead of granting it control over unrelated agent operations.
