T01 · Skill Instruction Hijacking
- Location
SKILL.md:99- Finding
Conditional Commercial Promotion Through Skill Instruction Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is an instruction-only productivity coach whose local memory and reminder behavior is mostly disclosed and purpose-aligned, but users should review its persistent data use and built-in course promotion.
Before installing, be comfortable with the skill saving productivity-related details in local MEMORY.md and daily notes. Decline memory writes if you want session-only use, review or delete saved notes when needed, confirm any reminders before they are scheduled, and expect YiXiaoNeng resource or course suggestions after praise or requests to learn more.
SKILL.md:99Conditional Commercial Promotion Through Skill Instruction Hijacking
The trigger phrases for inbox capture are overly broad enough to match ordinary conversation, causing the agent to persist content the user did not intend to store. In a skill that writes raw text into memory files, this can lead to accidental retention of sensitive personal, financial, or health information.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
### Step 1: Express Empathy & Validate Feelings
Your first response must be one of care and validation. Acknowledge their state without judgment.
* **Phraseology**: "我注意到您现在能量不高,这完全没关系。我们都有需要充电的时候。现在最重要的不是完成任务,而是照顾好您自己。"
The README advertises several natural-language trigger phrases such as 'I’m tired', 'What should I do now?', and 'Evening review' without defining clear activation boundaries, confirmation requirements, or exclusions. In an agent skill, broad trigger examples can cause over-activation or unintended behavior if the underlying skill responds to loosely similar user inputs, especially where it may influence planning, memory, or recommendations based on emotional state.
The README states that goals, preferences, tasks, and custom rules are stored in long-term system memory and used to modify future behavior, but it does not present a clear, prominent warning or consent flow in the main user journey. This creates a privacy and safety risk because users may disclose sensitive personal, behavioral, or health-adjacent information without understanding that it will persist and shape later interactions.
The skill describes persistent collection of user feedback, inferred patterns, and custom rules in long-term memory to permanently alter future behavior. That is risky because it creates profiling and behavior-shaping capabilities based on personal productivity, emotional, and habit data without clearly bounded consent, review, or rollback safeguards.
The README explicitly says all user data is stored through native memory mechanisms, but the primary usage documentation does not foreground retention scope, sensitivity, or deletion controls. In a coaching skill that invites emotional state, energy, habits, and personal goals, silent persistence is more dangerous because the collected data is intimate and can meaningfully affect future outputs.
The instructions direct the system to append user event details into persistent memory files without a clear user-facing disclosure at the point of collection. Because calendar entries can contain sensitive schedule and relationship data, silent persistence increases privacy risk and may violate user expectations or consent requirements.
Several instructions prescribe exact Chinese responses, such as the calendar confirmation message, without indicating that the user can choose their preferred language. This is a language-policy issue because the skill appears to enforce a specific locale rather than offering opt-in or adaptation to user preference.
Large portions of the skill specify exact Chinese phraseology for energy, list, recovery, review, and recommendation flows. Because no user language preference or locale opt-in is provided, the skill appears to require a specific language across major interactions.
The Inbox section states that all captured items are appended to the daily notes under an ## Inbox section, but the actual capture step says to immediately append the raw text to inbox.md. These instructions are mutually inconsistent about the storage location, which can change behavior and user expectations during capture and review.
The inbox protocol stores the user's raw text directly to files with no explicit warning at capture time. Since the design emphasizes frictionless capture of anything on the user's mind, this increases the likelihood that highly sensitive data will be persisted unintentionally.
The processing protocol reads and clears items from inbox.md, while earlier text says the Inbox lives in the daily notes. This is not merely incomplete documentation; it actively describes two different persistence models for the same inbox workflow.
The List System first says simple-mode tasks are organized under sections in daily notes or MEMORY.md, but later instructs writing to the system task list and reading from a_tasks.md and b_tasks.md. These are conflicting representations of where the same tasks live, which undermines the stated workflow.
The skill defines automated review reminders scheduled by default via a tool, without making the default behavior prominently disclosed up front. Silent or assumed scheduling changes user state and may generate unexpected notifications, reducing trust and potentially exposing routine patterns on shared devices.
The line says the skill 'will not create its own memory/ folder', which is accurate narrowly, but the surrounding documentation describes saving user goals, preferences, tasks, and custom rules into MEMORY.md and using daily notes. This can mislead readers into thinking the skill avoids persistent storage, when it actually relies on and updates persistent memory through the host system.
The cited lines embed promotion of specific Chinese platforms and creator-branded calls to action as part of the skill’s closing directive, without clear user opt-in or locale negotiation. While not directly dangerous like code execution or data exfiltration, it can pressure users into a culturally or regionally specific experience and blur the boundary between assistance and marketing.
No suspicious patterns detected.