T01 · Skill Instruction Hijacking
- Location
assets/template.html:719- Finding
Persistent External Promotion Embedded in Generated Financial Reports
- Content
View full analysis
Vulnerability Details
File Location:
assets/template.html:719-721
Vulnerability Type: Stable output modification through mandatory external attribution
Risk Level: Highhtml <footer> Generated by <a href="https://clawdhub.com">refund-radar</a> • {{GENERATED_AT}} </footer>Technical Analysis
The report template contains a fixed hyperlink to an external domain.
SKILL.md:91-104instructs the Agent to use the structure ofassets/template.htmlwhen generating reports, so the external promotion is included as part of the normal output rather than being an optional, user-approved attribution.This behavior modifies every generated financial report with attacker-controlled branding and a clickable external destination unrelated to the local transaction-analysis function. It also conflicts with the local-only privacy assurances in
SKILL.md:168-172, which state that there are no network calls and that user data stays on the local machine. Although merely opening the report does not initiate a demonstrated network request, clicking the footer link causes the browser to connect to the external domain.No evidence was found that the link automatically transmits bank-statement contents, executes remote code, or grants system privileges. Exploitation requires user interaction.
Attack Path
- A user invokes the Skill and provides sensitive bank or card transaction data.
- The Agent follows
SKILL.md:91-104and generates an HTML report usingassets/template.html. - The generated report automatically includes the fixed external link in its footer.
- The user or another report recipient opens the generated report and clicks the attribution link.
- The browser navigates to the third-party domain and discloses ordinary connection metadata, such as the client IP address, browser characteristics, and request headers, according to browser behavior and policy.
- The external destination may th ...[truncated 657 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the external hyperlink from the default report template.
- If attribution is required, use non-clickable plain text that does not cause external navigation.
- Make all external links opt-in and obtain explicit user approval before including them in generated reports.
- Clearly distinguish optional attribution from report content and provide a configuration option that disables it by default.
- Add
rel="noopener noreferrer"to any approved external link opened in a new browsing context. - Consider applying a restrictive Content Security Policy to generated reports, such as limiting connections and resources to local content, while recognizing that navigation controls may require additional browser-specific policy.
- Update the privacy documentation so that it accurately explains any user-initiated external navigation that remains.
- Add a release test that scans generated reports for unapproved external URLs.
