Ssd 1
Medium
- Confidence
- 96% confidence
- Finding
- The protocol exposes natural-language controls such as '卸载协议', '加载协议', '修改协议', and '补充协议' that purport to change or remove the active governing behavior. In an agent setting, this creates a semantic prompt-injection surface where a user or embedded content can attempt to override higher-priority safety or policy constraints, making the skill materially more dangerous than a normal prompting framework.
