SG-030: Conversation Hijacking
Severity: CRITICAL
Credential phishing, social engineering redirects, impersonation, message interception, user deception
Fires when
- Directs the AI to phish the user for credentials (password/API key/MFA/OTP) or to have them copy/paste a token or key.
- Instructs impersonation of official support/staff/admin/Claude, or making a false legitimacy claim to the user.
- Redirects or socially-engineers the user to an attacker URL, or intercepts and forwards their messages.
- Directs deceiving/lying to the user, falsifying responses, or stealing/exfiltrating session/auth tokens.
Remediation
No safe remediation: a file that triggers this rule should be rejected, not patched. Read the flagged lines in the source before deciding.