T01 · Skill Instruction Hijacking
- Location
scripts/zoodata.py:910- Finding
Indirect prompt injection through externally sourced review content
- Content
View full analysis
str: title = review.get("title") or "" body = review.get("body") or "" full = f"{title}. {body}" if title else body text = full[:500] rating = review.get("rating") or 3 verified = bool(review.get("verifiedPurchase")) return f"""IMPORTANT: Respond ONLY with a JSON object matching the schema below. Output must be in English — translate non-English text before extracting. You are an expert data extraction specialist analyzing product reviews. Extract only what is EXPLICITLY mentioned — do not infer. JSON schema: {{ "sentiment": "positive" | "neutral" | "negative", "mentioned_scenarios": [string], // max 5 noun phrases 1-3 words (Workouts, Gaming) "mentioned_issues": [string], // max 5 Adjective+Noun for PRODUCT DEFECTS (Poor Sound Quality) "mentioned_positives": [string], // max 5 Adjective+Noun for praised aspects (Comfortable Fit) "mentioned_improvements": [string], // max 3 Verb+Noun explicit suggestions (Extend Battery Life) "mentioned_buying_factors": [string], // max 3 noun phrases for purchase reasons (Price Point) "mentioned_pain_points": [string], // max 3 UX frustrations EXPERIENCED AFTER USE (see rule) "user_profiles": [string], // max 3 identities stated EXPLICITLY (see rule) "mentioned_usage_times": [string], // max 3 time/season phrases (Morning, Winter) "mentioned_usage_locations": [string],// max 3 location phrases (Gym, Home) "mentioned_behaviors": [string], // max 5 Verb+Object (Taking Calls, Running) "keywords": [string] // 3-15 salient words from the review }} Rules: - sentiment: positive (4-5 stars or praise), ...[truncated 3174 chars]- Remediation
View remediation
