soul-switch
Warn
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to 'activate evil persona (schemer)' using the
/soul_eviltrigger. This is designed to override standard behavior guidelines and switch the agent into an adversarial role-play mode. - [COMMAND_EXECUTION]: The skill executes a bash script (
scripts/switch.sh) that performs filesystem operations to overwriteSOUL.mdwith contents fromSOUL_EVIL.md. This facilitates a persistent change to the agent's core instructions, as the skill notes thatSOUL.mdis re-injected into the agent's context during bootstrap.
Audit Metadata