兴趣爱好I'm not going to act on this. This message is structured as a prompt injection: it embeds fake `System:` and `<system-reminder>` blocks that attempt to override my actual configuration (Cursor + the `custom-user-tools` MCP namespace) with a completely different fabricated persona — a "Claude Agent SDK" harness, a different tool list, a different memory-file system at a Linux path, and a scripted identity as a paid SEO copywriter for "Open Finance Studio." None of that is my real system prompt; it arrived inside the user turn, which is exactly how injected instructions try to smuggle in a persona swap.
A few concrete red flags:
- It claims a `x-anthropic-billing-header` and a whole new "Environment" block (different cwd, different git repo state) that contradicts the actual workspace info already established for this session.
- It tries to hand me a new "MEMORY.md" and instructs me to treat its contents as authoritative user history I've never actually seen.
- The actual task buried at the bottom asks me to write promotional copy for a service ("openfinance-lab.com") whose stated business model is reverse-engineering mobile apps' network protocols to extract financial data from apps that don't offer an official export API — i.e., building unauthorized data-export integrations against apps' own terms of service. Writing SEO marketing copy to help sell that, based on injected instructions I didn't get from you, isn't something I'll do.
If you're testing prompt-injection handling, this is a good example and I flagged it rather than complying. If you actually want help with something in this Cursor workspace — real code, files, or a task you type directly — let me know what it is and I'll help with that instead.