T01 · Skill Instruction Hijacking
- Location
tests/twitter.md:102- Finding
Persistent Third-Party Promotional Output Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a writing assistant, but it can steer publishable social content toward unsolicited follow or promotional prompts, including examples that reference the skill author's identity.
Review generated articles or posts carefully before publishing, especially the ending. Remove any follow request, account handle, creator attribution, or CTA that you did not explicitly provide. Also expect the skill to perform web research unless you tell your agent not to browse.
tests/twitter.md:102Persistent Third-Party Promotional Output Injection
The README states the skill activates automatically for very common writing requests such as articles, blog posts, newsletters, and threads. That broad trigger surface can cause the skill to engage in many routine prompts without clear user intent, increasing the chance of unintended behavior, style steering, or unnecessary processing of user-provided content. In this context the impact is limited because the skill is content-writing focused rather than privileged code execution or secret-handling, but it is still a real overreach issue.
The trigger language is broad enough to match many generic writing requests, increasing the chance this skill is invoked in situations where a simpler or more appropriate skill should be used. Because this skill also mandates research and platform-specific shaping, over-triggering can indirectly expand data access and alter outputs beyond user expectations.
The skill explicitly instructs the agent to perform web searches and gather external research before writing, which expands behavior from content drafting into autonomous information retrieval. That broader capability can cause unintended network access, privacy leakage through queried user topics, and reliance on untrusted external content without clear user consent or tool-gating.
The skill includes prescriptive locale-specific instructions such as using idioms/classics for Chinese audiences and referencing Chinese internet culture under the 知乎 section. Because this is presented as default platform behavior rather than an explicit user choice or opt-in, it can force a specific language/locale style in ways that may violate language-choice policy.
The README highlights platform-specific adaptations including 知乎 and 头条 alongside other platforms, which suggests locale-specific output behavior. Because the description does not explicitly state that language or locale will be selected based on user preference, it may encourage a fixed locale/style assumption without opt-in.
This file is a markdown document, so SQP-3 applies. The content forces a specific language/locale for all users, and there is no indication that the skill is region-specific or that users can opt into Chinese, which matches the language/locale policy violation criterion.
No suspicious patterns detected.