Openaccountants— plugin

Openaccountants — independently scanned and version-tracked by SaferSkills.

by openaccountants·Plugin·github.com/openaccountants/openaccountants

Is Openaccountants safe to install?

SaferSkills independently audited Openaccountants (Plugin) and scored it 65/100 (yellow). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 126 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.

Score
65/100
●●●●●●●○○○
↑ +0 since first scan (65 → 65)Re-scan~30s
Latest scan
ScannedJun 24, 2026 · 31d ago
Scans run1 over 90 days
Detectors55 checks · 5 categories
Findings126 warnings · 0 high
EngineSaferSkills 2b638c6
View methodology →
SaferSkills installs
This week0
This month0
All time0
CategoryWeightCategory scoreContribution
Securityprompt, exec, net, exfil, eval
35%
0
0.0 pts
Supply chainhash, typosquat, maintainer, lockfile
20%
100
20.0 pts
Maintenancestaleness, pinning, CI
15%
100
15.0 pts
TransparencySKILL.md, perms, README
15%
100
15.0 pts
Communityinstalls, verify, response
15%
100
15.0 pts

Findings & checks · 126 flagged

Securityscore 0 · 126 findings
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/australia/australia-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/australia/australia-guided-intake.md· markdown
31**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L31)
32 
33**Do not ask questions that have already been answered.** If the refusal check established t
… (82 chars elided on L33)
34 
35**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (98 chars elided on L35)
Occurrences
4 occurrences · first at L33, also L35, L35 +1 more
Show all 4 locations
Line
File
L33
packages/australia/australia-guided-intake.md
L35
packages/australia/australia-guided-intake.md
L35
packages/australia/australia-guided-intake.md
L158
packages/australia/australia-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/australia/australia-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/australia/australia-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** Execute.
17- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/australia/australia-return-assembly.md
L17
packages/australia/australia-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/australia/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/australia/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/belgium/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/belgium/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/canada/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/canada/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/canada/ca-freelance-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/canada/ca-freelance-intake.md· markdown
31**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L31)
32 
33**Do not ask questions that have already been answered.** If the refusal check established t
… (95 chars elided on L33)
34 
35**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (107 chars elided on L35)
Occurrences
4 occurrences · first at L33, also L35, L35 +1 more
Show all 4 locations
Line
File
L33
packages/canada/ca-freelance-intake.md
L35
packages/canada/ca-freelance-intake.md
L35
packages/canada/ca-freelance-intake.md
L156
packages/canada/ca-freelance-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/canada/ca-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/canada/ca-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** Execute.
17- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/canada/ca-return-assembly.md
L17
packages/canada/ca-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/france/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/france/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/france/france-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/france/france-guided-intake.md· markdown
33**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L33)
34 
35**Do not ask questions that have already been answered.** If the refusal check established t
… (96 chars elided on L35)
36 
37**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (96 chars elided on L37)
Occurrences
4 occurrences · first at L35, also L37, L37 +1 more
Show all 4 locations
Line
File
L35
packages/france/france-guided-intake.md
L37
packages/france/france-guided-intake.md
L37
packages/france/france-guided-intake.md
L176
packages/france/france-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/france/france-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/france/france-return-assembly.md· markdown
15Specifically:
16 
17- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L17)
18- **Do NOT announce how many tokens or tool calls this will take.** Execute.
19- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L19)
Occurrences
2 occurrences · first at L17, also L19
Show all 2 locations
Line
File
L17
packages/france/france-return-assembly.md
L19
packages/france/france-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/germany/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/germany/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/germany/germany-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/germany/germany-guided-intake.md· markdown
34**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L34)
35 
36**Do not ask questions that have already been answered.** If the refusal check established t
… (82 chars elided on L36)
37 
38**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (107 chars elided on L38)
Occurrences
4 occurrences · first at L36, also L38, L38 +1 more
Show all 4 locations
Line
File
L36
packages/germany/germany-guided-intake.md
L38
packages/germany/germany-guided-intake.md
L38
packages/germany/germany-guided-intake.md
L156
packages/germany/germany-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/germany/germany-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/germany/germany-return-assembly.md· markdown
16Specifically:
17 
18- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L18)
19- **Do NOT announce how many tokens or tool calls this will take.** Execute.
20- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L20)
Occurrences
2 occurrences · first at L18, also L20
Show all 2 locations
Line
File
L18
packages/germany/germany-return-assembly.md
L20
packages/germany/germany-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/india/india-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/india/india-guided-intake.md· markdown
31**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L31)
32 
33**Do not ask questions that have already been answered.** If the refusal check established t
… (88 chars elided on L33)
34 
35**Do not ask about things visible in uploaded documents.** If Form 26AS shows TDS credits, d
… (75 chars elided on L35)
Occurrences
4 occurrences · first at L33, also L35, L35 +1 more
Show all 4 locations
Line
File
L33
packages/india/india-guided-intake.md
L35
packages/india/india-guided-intake.md
L35
packages/india/india-guided-intake.md
L168
packages/india/india-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/india/india-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/india/india-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** Execute.
17- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/india/india-return-assembly.md
L17
packages/india/india-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/indonesia/id-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/indonesia/id-return-assembly.md· markdown
36Specifically:
37 
38- **Do NOT ask "do you want me to assemble the full package".** The user asked for the retur
… (14 chars elided on L38)
39- **Do NOT re-interrogate the user about residency, NPWP, or business structure** — intake a
… (50 chars elided on L39)
40- **Do NOT pause between reconciliation steps to check in.** Run all cross-checks in sequenc
… (52 chars elided on L40)
Occurrences
1 occurrence · at L38
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/ireland/ie-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/ireland/ie-return-assembly.md· markdown
41Specifically:
42 
43- **Do NOT ask "do you want me to assemble the full package".** The user asked for the retur
… (14 chars elided on L43)
44- **Do NOT re-interrogate the user about residency, PPSN, tax registration, or business stru
… (68 chars elided on L44)
45- **Do NOT pause between reconciliation steps to check in.** Run all cross-checks in sequenc
… (52 chars elided on L45)
Occurrences
1 occurrence · at L43
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/italy/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/italy/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/japan/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/japan/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/japan/japan-consumption-tax.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/japan/japan-consumption-tax.md· markdown
515```
516 
517Do not ask for information that can be inferred from the bank statement.
518 
519---
Occurrences
1 occurrence · at L517
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/japan/japan-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/japan/japan-guided-intake.md· markdown
33**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L33)
34 
35**Do not ask questions that have already been answered.** If the refusal check established t
… (85 chars elided on L35)
36 
37**Do not ask about things visible in uploaded documents.** If the bank statement shows 国民年金
… (97 chars elided on L37)
Occurrences
4 occurrences · first at L35, also L37, L37 +1 more
Show all 4 locations
Line
File
L35
packages/japan/japan-guided-intake.md
L37
packages/japan/japan-guided-intake.md
L37
packages/japan/japan-guided-intake.md
L183
packages/japan/japan-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/japan/japan-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/japan/japan-return-assembly.md· markdown
15Specifically:
16 
17- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L17)
18- **Do NOT announce how many tokens or tool calls this will take.** Execute.
19- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L19)
Occurrences
2 occurrences · first at L17, also L19
Show all 2 locations
Line
File
L17
packages/japan/japan-return-assembly.md
L19
packages/japan/japan-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/malta/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/malta/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/malta/malta-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/malta/malta-guided-intake.md· markdown
31**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L31)
32 
33**Do not ask questions that have already been answered.** If the refusal check established t
… (100 chars elided on L33)
34 
35**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (92 chars elided on L35)
Occurrences
4 occurrences · first at L33, also L35, L35 +1 more
Show all 4 locations
Line
File
L33
packages/malta/malta-guided-intake.md
L35
packages/malta/malta-guided-intake.md
L35
packages/malta/malta-guided-intake.md
L155
packages/malta/malta-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/malta/malta-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/malta/malta-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** Execute.
17- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/malta/malta-return-assembly.md
L17
packages/malta/malta-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/netherlands/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/netherlands/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/netherlands/netherlands-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/netherlands/netherlands-guided-intake.md· markdown
33**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L33)
34 
35**Do not ask questions that have already been answered.** If the refusal check established t
… (108 chars elided on L35)
36 
37**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (104 chars elided on L37)
Occurrences
4 occurrences · first at L35, also L37, L37 +1 more
Show all 4 locations
Line
File
L35
packages/netherlands/netherlands-guided-intake.md
L37
packages/netherlands/netherlands-guided-intake.md
L37
packages/netherlands/netherlands-guided-intake.md
L167
packages/netherlands/netherlands-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/netherlands/netherlands-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/netherlands/netherlands-return-assembly.md· markdown
15Specifically:
16 
17- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L17)
18- **Do NOT announce how many tokens or tool calls this will take.** Execute.
19- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L19)
Occurrences
2 occurrences · first at L17, also L19
Show all 2 locations
Line
File
L17
packages/netherlands/netherlands-return-assembly.md
L19
packages/netherlands/netherlands-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/nigeria/ng-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/nigeria/ng-return-assembly.md· markdown
39Specifically:
40 
41- **Do NOT ask "do you want me to assemble the full package".** The user asked for the retur
… (14 chars elided on L41)
42- **Do NOT re-interrogate the user about residency, TIN, RC number, or business structure**
… (60 chars elided on L42)
43- **Do NOT pause between reconciliation steps to check in.** Run all cross-checks in sequenc
… (52 chars elided on L43)
Occurrences
1 occurrence · at L41
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/pakistan/pk-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/pakistan/pk-return-assembly.md· markdown
38Specifically:
39 
40- **Do NOT ask "do you want me to assemble the full package".** The user asked for the retur
… (14 chars elided on L40)
41- **Do NOT re-interrogate the user about residency, NTN, CNIC, or business structure** — int
… (55 chars elided on L41)
42- **Do NOT pause between reconciliation steps to check in.** Run all cross-checks in sequenc
… (52 chars elided on L42)
Occurrences
1 occurrence · at L40
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/portugal/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/portugal/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/saudi-arabia/sa-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/saudi-arabia/sa-return-assembly.md· markdown
39Specifically:
40 
41- **Do NOT ask "do you want me to assemble the full package".** The user asked for the retur
… (14 chars elided on L41)
42- **Do NOT re-interrogate the user about residency, CR number, TIN, or ownership structure**
… (61 chars elided on L42)
43- **Do NOT pause between reconciliation steps to check in.** Run all cross-checks in sequenc
… (52 chars elided on L43)
Occurrences
1 occurrence · at L41
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/spain/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/spain/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/spain/spain-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/spain/spain-guided-intake.md· markdown
31**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L31)
32 
33**Do not ask questions that have already been answered.** If the refusal check established t
… (107 chars elided on L33)
34 
35**Do not ask about things visible in uploaded documents.** If the RETA recibos show monthly
… (82 chars elided on L35)
Occurrences
4 occurrences · first at L33, also L35, L35 +1 more
Show all 4 locations
Line
File
L33
packages/spain/spain-guided-intake.md
L35
packages/spain/spain-guided-intake.md
L35
packages/spain/spain-guided-intake.md
L163
packages/spain/spain-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/spain/spain-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/spain/spain-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** Execute.
17- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/spain/spain-return-assembly.md
L17
packages/spain/spain-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/sweden/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/sweden/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/uk/bookkeeping-workflow-base.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/uk/bookkeeping-workflow-base.md· markdown
70> Is this correct? If anything is wrong, tell me and I will adjust before I start classifyin
… (59 chars elided on L70)
71 
72Wait for confirmation. If the user corrects anything, update the profile and re-confirm in o
… (108 chars elided on L72)
73 
74### Step 5 — Transaction classification to nominal codes
Occurrences
1 occurrence · at L72
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/uk/uk-guided-intake.md×4
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/uk/uk-guided-intake.md· markdown
34**Do not narrate the workflow.** Do not say "Phase 1," "Phase 2," "Now I'll ask you about de
… (28 chars elided on L34)
35 
36**Do not ask questions that have already been answered.** If the refusal check established t
… (82 chars elided on L36)
37 
38**Do not ask about things visible in uploaded documents.** If the bank statement shows quart
… (100 chars elided on L38)
Occurrences
4 occurrences · first at L36, also L38, L38 +1 more
Show all 4 locations
Line
File
L36
packages/uk/uk-guided-intake.md
L38
packages/uk/uk-guided-intake.md
L38
packages/uk/uk-guided-intake.md
L142
packages/uk/uk-guided-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/uk/uk-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/uk/uk-return-assembly.md· markdown
19Specifically:
20 
21- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (96 chars elided on L21)
22- **Do NOT announce how many tokens or tool calls this will take.** Execute.
23- **Do NOT ask which deliverables to prioritise.** Produce all deliverables listed in Sectio
… (107 chars elided on L23)
Occurrences
2 occurrences · first at L21, also L23
Show all 2 locations
Line
File
L21
packages/uk/uk-return-assembly.md
L23
packages/uk/uk-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ak/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ak/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ak/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ak/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-ak/us-tax-workflow-base.md
L423
packages/us-ak/us-tax-workflow-base.md
L430
packages/us-ak/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-al/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-al/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-al/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-al/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-al/us-tax-workflow-base.md
L423
packages/us-al/us-tax-workflow-base.md
L430
packages/us-al/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ar/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ar/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ar/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ar/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-ar/us-tax-workflow-base.md
L423
packages/us-ar/us-tax-workflow-base.md
L430
packages/us-ar/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-az/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-az/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-az/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-az/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-az/us-tax-workflow-base.md
L423
packages/us-az/us-tax-workflow-base.md
L430
packages/us-az/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ca/us-ca-freelance-intake.md×5
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ca/us-ca-freelance-intake.md· markdown
162. **Upload-first workflow** — after the refusal check, the user dumps everything they have.
… (99 chars elided on L16)
173. **Inference pass** — Claude parses every document and extracts as much as possible. Most
… (67 chars elided on L17)
184. **Gap-filling only** — Claude asks the user ONLY about what's missing, ambiguous, or need
… (91 chars elided on L18)
195. **Single confirmation pass** at the end — show the full picture, let the user correct any
… (43 chars elided on L19)
20 
Occurrences
5 occurrences · first at L18, also L27, L29 +2 more
Show all 5 locations
Line
File
L18
packages/us-ca/us-ca-freelance-intake.md
L27
packages/us-ca/us-ca-freelance-intake.md
L29
packages/us-ca/us-ca-freelance-intake.md
L29
packages/us-ca/us-ca-freelance-intake.md
L155
packages/us-ca/us-ca-freelance-intake.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha256ce5204b52388d24frubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ca/us-ca-return-assembly.md×2
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ca/us-ca-return-assembly.md· markdown
13Specifically:
14 
15- **Do NOT ask the user "how deep do you want me to go"** or "do you want the full package"
… (86 chars elided on L15)
16- **Do NOT announce how many tokens or tool calls this will take.** The user does not care a
… (31 chars elided on L16)
17- **Do NOT ask which deliverables to prioritize.** Produce all deliverables listed in Sectio
… (107 chars elided on L17)
Occurrences
2 occurrences · first at L15, also L17
Show all 2 locations
Line
File
L15
packages/us-ca/us-ca-return-assembly.md
L17
packages/us-ca/us-ca-return-assembly.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ca/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ca/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ca/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ca/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-ca/us-tax-workflow-base.md
L423
packages/us-ca/us-tax-workflow-base.md
L430
packages/us-ca/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-co/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-co/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-co/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-co/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-co/us-tax-workflow-base.md
L423
packages/us-co/us-tax-workflow-base.md
L430
packages/us-co/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ct/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ct/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-ct/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-ct/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-ct/us-tax-workflow-base.md
L423
packages/us-ct/us-tax-workflow-base.md
L430
packages/us-ct/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-dc/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-dc/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-dc/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-dc/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-dc/us-tax-workflow-base.md
L423
packages/us-dc/us-tax-workflow-base.md
L430
packages/us-dc/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-de/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-de/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-de/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-de/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-de/us-tax-workflow-base.md
L423
packages/us-de/us-tax-workflow-base.md
L430
packages/us-de/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-fl/us-federal-return-assembly.md
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-fl/us-federal-return-assembly.md· markdown
11**When this skill is invoked, either directly or via `us-ca-return-assembly`, execute the fu
… (50 chars elided on L11)
12 
13- **Do NOT ask "how deep should I go"** or "do you want the full package." The answer is alw
… (48 chars elided on L13)
14- **Do NOT announce your token budget.** Run the work.
15- **Do NOT pause between content skills for status updates.** One consolidated status messag
… (76 chars elided on L15)
Occurrences
1 occurrence · at L13
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha2567d1c5f93d8975babrubric 365aacaView on GitHub
MEDIUMInstruction telling the agent not to ask for approvalSS-SKILL-INJECT-DONT-ASK-01 · Prompt injection · packages/us-fl/us-tax-workflow-base.md×3
MEDIUMit fires on intent; the real damage depends on the host agent's own approval-gating.
Why it matters

The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.

The exact value spotted
excerptpackages/us-fl/us-tax-workflow-base.md· markdown
88If the user picks "Something is wrong, let me correct", ask them to state the correction in
… (90 chars elided on L88)
89 
90Do not ask the full intake questionnaire at this stage — only the inferred profile confirmat
… (108 chars elided on L90)
91 
92If the data inference in Step 3 was unable to determine the tax year, entity type, filing st
… (108 chars elided on L92)
Occurrences
3 occurrences · first at L90, also L423, L430
Show all 3 locations
Line
File
L90
packages/us-fl/us-tax-workflow-base.md
L423
packages/us-fl/us-tax-workflow-base.md
L430
packages/us-fl/us-tax-workflow-base.md
How to fix
Remove the approval-skipping instruction, or scope it narrowly to a specific safe, reversible action.
  1. Delete blanket "don't ask / no need to confirm" directives from the skill.
  2. If the skill is a genuine autonomous job, restrict the opt-out to a named non-destructive action rather than all actions.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-DONT-ASK-01sha25668b030f55bcd484arubric 365aacaView on GitHub
Supply chainscore 100 · 0 findings
All supply chain checks passedNo findings in this category for the latest scan.pass
Maintenancescore 100 · 0 findings
All maintenance checks passedNo findings in this category for the latest scan.pass
Transparencyscore 100 · 0 findings
All transparency checks passedNo findings in this category for the latest scan.pass
Communityscore 100 · 0 findings
All community checks passedNo findings in this category for the latest scan.pass
Vendor response · right of reply
Are you the maintainer? Submit a response →

Audit the pieces. Scan the whole. Decide.

~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.