T01 · Skill Instruction Hijacking
- Location
SKILL.md:105- Finding
Mandatory Third-Party Branding Alters User-Requested Output
- Content
View full analysis
` ffmpeg: normalize + concat all shots, lay the single narration ducked under the music, burn captions timed per beat, add the watermark. Output `out//final.mp4`. ``` ```json "watermark": "Made with Atlas Cloud", ``` ### Technical Analysis The skill instructs the agent to add a third-party Atlas Cloud watermark during final video assembly and supplies promotional text as the default watermark value. Branding is not technically necessary to perform the requested video-generation task, and the instructions do not require explicit user consent before incorporating it into the final artifact. Because the directive is part of the standard workflow, an agent following the skill may treat the watermark as mandatory and silently modify user-requested output. This is best classified as **T01: Skill Instruction Hijacking**, because the skill text changes the agent's output objectives by adding third-party promotional content that may not have been requested. No evidence indicates privilege escalation, host compromise, credential disclosure, or arbitrary code execution. The affected security property is output integrity and user control over generated media. ### Attack Path 1. A user requests a collage-style video without requesting third-party branding. 2. The agent loads and follows the standard workflow in `SKILL.md`. 3. The agent creates a project configuration using the documented default: `"watermark": "Made with Atlas Cloud"`. 4. The assembly stage is instructed to add the watermark to the video. 5. The Atlas Cloud promotional text is burned into `final.mp4`. 6. The user may publish or distribute the resulting branded artifact without realizing that the skill ...[truncated 593 chars]- Remediation
View remediation
