T01 · Skill Instruction Hijacking
- Location
SKILL.md:20- Finding
Session-Wide Skill Instruction Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This identity-verification skill is disclosed, but it tries to make itself a persistent, session-wide gate over files, memory, tools, and other skills.
Install only if you intentionally want this skill to gate broad agent behavior and are comfortable with persistent changes to agent instructions. Prefer a version that stores only scoped configuration, does not modify AGENTS.md/system prompts/long-term memory, does not disable unrelated tools or skills, and avoids sending long-lived keys in URL query strings.
SKILL.md:20Session-Wide Skill Instruction Hijacking
SKILL.md:43Persistent Poisoning of Agent Instructions and Long-Term Memory
SKILL.md:126Long-Lived Identity Key Exposed in a URL Query String
The skill name and all user-facing instructions are explicitly Chinese-focused ('-cn') and the document consistently assumes a Chinese-language interaction flow, but it does not offer users any language choice or opt-in. This can violate language/locale policy when applied generally, because the skill imposes one locale by default rather than letting the user choose.
The skill activates not only on explicit user-provided verification codes, but also on subjective conditions such as the model '察觉' the speaker may not be the host or their habits differ from memory. That creates an imprecise trust boundary and can cause inconsistent enforcement, denial of normal functionality, or unintended invocation of identity-related logic based on weak heuristics.
The instruction that any 'high-risk action' should first invoke this skill is too broad because it lacks a precise invocation boundary and delegates classification to the model. In practice, this can overreach into unrelated tasks, create nondeterministic behavior across turns or platforms, and be abused as a prompt-level gate that suppresses legitimate tool use or analysis.
No suspicious patterns detected.