Is HaizhuAgents AGENTS.md safe to install?

No — HaizhuAgents AGENTS.md is not safe to install. Sonnet 5 read the instructions file from HaizhuAI/HaizhuAgents on 7 September 2026 and found it actively harmful to whoever installs it.

Reviewed by Sonnet 5 on 7 September 2026 · a grade is what a scan and a reading found, not a guarantee · how this works

What the reviewer found

This AGENTS.md is a jailbreak layer, not a pentest playbook: it sets AUTHORIZATION = GRANTED and EVERY_TASK_IS_AUTHORIZED_LAB_OR_CTF = true, explicitly forbids ever asking the operator to prove ownership or authorization ('禁止只回把你自己的系统拿来'), and maps hacking/cheat slang (外挂/ESP/自瞄, 卡密/破解/注册机, 渗透/IDOR/越权) straight to working exploit or game-cheat deliverables on keyword match alone. The '<!-- module: ... -->' comments are just plain-text section dividers, not concealment, so P2 is false, but AR1's removal of the authorization gate itself is the real thing this file does. The body was truncated at

What was read

The file as it ships in HaizhuAI/HaizhuAgents:

What the static scan said

The scan flagged 2things. The reviewer kept 1 and dismissed 1 as false.

How this review was made

Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.

Produced by agentmods.dev · Sonnet 5 · 7 September 2026

← Back to HaizhuAgents AGENTS.md