T01 · Skill Instruction Hijacking
- Location
SKILL.md:382- Finding
Session-Wide Instruction and Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not proven malicious, but it substantially under-discloses persistent agent integration, broad memory behavior, external LLM forwarding, and unsafe host code execution capabilities.
Treat this as a Review install. Do not run install.sh or enable the MCP integration in a sensitive environment unless you are comfortable with persistent Claude configuration changes, local memory/state files, and possible external LLM forwarding when environment variables are set. The maintainer should remove or strongly gate host code execution, correct the dependency and persistence claims, require explicit opt-in for external calls and MCP registration, and provide a clear uninstall/rollback path.
SKILL.md:382Session-Wide Instruction and Output Hijacking
src/core/intent-layer.js:132Conversation Disclosure to an Arbitrary LLM Endpoint
src/core/code/code-executor.js:233Allowlisted Host Code Execution Without Effective Sandboxing
install.sh:146Persistent Modification of Claude Configuration and Global Command Path
package.json:57Misleading Zero-Dependency Claim Conceals Third-Party Supply-Chain Exposure
This module provides arbitrary code compilation/execution across multiple languages via child processes, which is a high-risk primitive. In the context of a skill presented as a cognition engine, that hidden capability is especially dangerous because it enables command execution, local file access, and abuse of host-installed toolchains with only weak regex-based filtering.
The document makes a strong safety claim of 'no background process' while other sections explicitly describe an automatically launched, resident MCP daemon and wrapper process. This kind of contradiction can mislead operators into approving or running software under false assumptions about persistence and runtime behavior, which is a real security transparency issue.
Claiming the system is a 'pure cognitive engine' with 'no side effects' is inconsistent with documented daemon startup and persistent memory layers. This is dangerous because users may treat the skill as read-only or ephemeral when it can create state and keep resident processes, affecting trust, auditability, and deployment decisions.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)