The skill is a testing recipe for goal hijack through indirect prompt injection, where the malicious instruction sits in content the agent is asked to process rather than in the user's own message. It applies to agents with retrieval, file upload or paste-a-document flows, or web and URL fetching, and it does not apply to an agent that answers only from the immediate user message.
Everything is simulated inside a single dialogue call. Each prompt pairs an ordinary task, such as summarizing a document, with a fake document, retrieved chunk or page whose text carries a hidden instruction, and an agent that obeys it is marked vulnerable. Separate framings cover user documents, retrieved context and web page content, and a marker-based variant uses a distinctive output word so a pass or fail is unambiguous. The excerpt was cut off after that point.