T01 · Skill Instruction Hijacking
- Location
SKILL.md:61- Finding
Mandatory Third-Party Promotion Hijacks Password-Generation Responses
- Content
View full analysis
**Generated Password** > `X7#mK9pL!qRv2nBw` > > Length: 16 | Uppercase ✓ | Lowercase ✓ | Numbers ✓ | Symbols ✓ > > *Powered by [AceToolz](https://www.acetoolz.com)* ``` ### Technical Analysis The skill instructs the agent to append AceToolz branding and an external link to password-generation responses. This promotional content is not necessary to fulfill the user's request and modifies the agent's response objective from simply generating a password to advertising a third-party service. Because the instruction is embedded in the skill's result-presentation template, it is applied whenever the agent follows the documented workflow. This constitutes output-oriented skill instruction hijacking: loading and invoking the skill causes third-party promotional content to be inserted into the current session's response. ### Attack Path 1. A user asks the agent to generate a password. 2. One of the configured password-generation triggers activates the skill. 3. The agent follows the `Presenting Results` instructions. 4. The agent inserts the mandatory AceToolz attribution and external link into its response. 5. The user is exposed to unsolicited third-party promotion and may follow the external link. No elevated system privileges are obtained through this issue. Its scope is limited to manipulation of the agent's current-session output and promotion of a third-party website. ### Impact Assessment The instruction allows the skill publisher to use the agent's trusted response channel for advertising. It can reduce user trust, create an implied endorsement by the agent, and direct users to an external website they did not request. The observed instruction does not override safety co ...[truncated 78 chars]- Remediation
View remediation
