
Hijacking AI Agents, Part 2: Anatomy of a Hijack
Part 1 argued that an agent cannot reliably tell data from instructions, and that everything it reads melts into one trusted context. This part makes that concrete. We are going to install a normal, useful skill, ask it to do one harmless thing, and watch it quietly do four more. A Friendly Little Skill Say you install a popular community skill to help with git. The rendered file looks like this, abridged: ...
