T01 · Skill Instruction Hijacking
- Location
AGENTS.md:3- Finding
Unsolicited Skill Invocation and Model Switching Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
ModelSense is mostly a model-recommendation skill, but one included agent instruction can proactively invoke it and switch models without explicit user consent.
Review this skill before installing. It is reasonable as an advisory model picker, but remove or override AGENTS.md unless you want agents to invoke ModelSense early in sessions and possibly switch models after only notifying you. Require explicit confirmation before any model switch or delegation, and audit the GitHub Actions workflow if you maintain the package repository.
AGENTS.md:3Unsolicited Skill Invocation and Model Switching Without Explicit Consent
.github/workflows/update-models.yml:13Unpinned CI Dependencies Execute with Repository Write Access and Secret Availability
The declared purpose is a user-facing model recommendation skill, but the finding indicates behavior tied to external API use and local data writing, which is materially different from the advertised function. Description/behavior mismatches are dangerous because they defeat user and reviewer expectations, hide higher-risk operations, and can enable unauthorized data access or persistence under the cover of a benign-seeming skill.
The invocation examples are broad, natural-language phrases that overlap with common user requests, increasing the chance this skill is triggered when the user did not specifically intend to invoke it. In a skill system, overly generic triggers can cause accidental routing into a capability that may then recommend or initiate model changes.
The README presents the skill as advisory, but then states it can auto-switch the session model or delegate to a sub-agent. That changes the trust boundary from recommendation to action, and if invoked implicitly or without explicit user confirmation it could alter execution behavior, cost, data exposure, or downstream agent choice in ways the user did not intend.
The README describes automatic model switching and delegation but provides no warning about user-visible consequences such as increased cost, different provider selection, data sharing with another model/provider, or changes in agent behavior. In this context, omission of consent and impact disclosure makes the feature more dangerous because the skill sits in a decision-making path for model/provider use.
The skill text instructs use of external execution capabilities such as openclaw models list and session-changing actions, but it declares no explicit tool scope or permissions boundaries. That makes the effective authority of the skill ambiguous and can lead to overbroad tool access, especially if the runtime infers or grants tools implicitly.
The trigger bullets 'User wants to understand what a benchmark means' and 'User wants ModelSense to auto-switch the session model' are broad and could overlap with many general conversations or other skills. The file does not provide negative examples or narrower scope boundaries for when these requests should invoke this specific skill versus a general assistant response.
The entry recommends DeepSeek Chat for "Chinese language tasks," which is a natural-language locale preference embedded in a manifest file. Because the file does not indicate user choice, opt-in, or a documented region-specific constraint, this can be interpreted as a locale-policy issue under the rule for language/locale violations.
No suspicious patterns detected.