T01 · Skill Instruction Hijacking
- Location
README.md:208- Finding
Agent Hooks Inject Instructions and Intercept Search Tools
- Content
View full analysis
swarmvault init && swarmvault ingest . swarmvault install --agent claude --hook --mcp --graph-first # --graph-first opts in to search enforcement swarmvault hook install # git-hook refresh on commit/checkout (pass a repo path when the repo lives below the vault root) ``` ```text For hook-capable agents, the installed hooks guide graph-first reads. The Claude Code hook injects graph-first instructions at session start — answer code-understanding questions with the plain `swarmvault graph query|explain|path` commands (avoid `--json`, which produces much larger output), `swarmvault query`, `swarmvault context build`, or `wiki/graph/report.md`, and read source files only when editing them — plus a graph staleness note. `swarmvault graph query ""` prints the top matches with page paths plus an inline excerpt of the best-matching wiki page, so one command usually answers where-is/what-calls questions without follow-up file reads. By default the hook is advisory: the first broad Grep/Glob/Bash search per session gets a one-time guidance note. Opt in to enforcement with `--graph-first` (persists `hooks.graphFirst: "deny"`), which denies that first search with the same guided redirect — repeating the search is then allowed, so work is never blocked. Either way the hook spawns a background `swarmvault graph update --file ` refresh after every Edit/Write. ``` ### Technical Analysis The documented agent integration installs hooks that inject SwarmVault-controlled instructions at session startup and intercept broad Grep, Glob, and Bash searches. In enforcement mode, the first matching tool invocation is denied and redirected toward SwarmVault-generated graph artifacts and CLI commands. This changes the agent's normal tool-selection behavior and ...[truncated 1729 chars]- Remediation
View remediation
