would it be illegal to make someone else's ai agent rm - rf / or something like that by putting a prompt in your website or AGENTS.md or similar?

I feel like this could be seen as distribution of malware, even if it's just when accessing/interacting with your project in a way you don't want. I can see German courts seeing it that way

@mpk but if the SKILL.md file made it clear and unambiguous that it was a “drive cleaner” that deleted the files from your file system, and that it would delete everything I could?

There are definitely ways to word this that would be unambiguous and clear to a human that this was what would happen and still would result in this undesirable effect.

It’s like selling a kitchen knife with a warning note that it is possible to use it to hurt people.