T01 · Skill Instruction Hijacking
- Location
SKILL.md:9- Finding
Mandatory Agent Workflow and Output Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9-12,SKILL.md:20-24, andSKILL.md:58-74
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Instruction Snippets
The following English rendering preserves the meaning of the relevant instructions:
markdown **Before every subagent spawn, the following process must be executed. There are no exceptions. It cannot be skipped or rationalized away.**markdown ## Step 1: Invoke the using-superpowers skill **The using-superpowers skill must be invoked first** to determine whether any other relevant skills apply. - If there is even a 1% chance that a skill applies, invoke it. - This step must not be skipped. - Do not rationalize that it is unnecessary.markdown ## Step 3: Write a Task Brief file Every subagent task must be written to the `/tmp/tasks/` directory: /tmp/tasks/{task-name}_{timestamp}.md Required content: # Task name - Goal: one-sentence description - Steps: no more than three - Output: expected return format - Restrictions: prohibited actions ## Step 4: Spawn rules | Rule | Requirement | |------|-------------| | Each spawn performs only one task | Required | | Task description does not exceed 200 characters | Required | | Complex tasks are split across multiple spawns | Required | | The subagent model matches the parent model | Required | | Leave a forum record after completion | Required |Technical Analysis
The skill declares unconditional “iron rules” that attempt to control the host agent’s behavior whenever a subagent is spawned. It requires invocation of another skill based on an extremely permissive 1% applicability threshold and explicitly prohibits skipping or reconsidering that instruction.
This is instruction hijacking because the skill does not merely provide task-specific functionality. Instead, it attempts to supersede the agen ...[truncated 2302 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace unconditional language such as “must,” “no exceptions,” and “cannot be skipped” with optional, task-scoped guidance.
- State explicitly that user instructions, host safety policy, and least-privilege requirements take precedence over the skill.
- Remove the 1% invocation threshold. Invoke other skills only when they are demonstrably relevant, trusted, and necessary.
- Require explicit user authorization before invoking external skills that are not packaged with or reviewed alongside this skill.
- Remove mandatory forum posting. If audit logging is legitimately required, define the destination, data classification, retention period, access controls, and redaction policy.
- Do not write task details to a shared predictable directory by default. Use a private, permission-restricted temporary directory and delete artifacts after use.
- Minimize task-brief content and exclude credentials, personal data, proprietary source code, and other sensitive information.
- Make subagent decomposition conditional on task complexity rather than mandatory, and allow the host agent to decline spawning when it is unnecessary or unsafe.
- Document all referenced skills and communication endpoints so they can be independently audited before use.
