T01 · Skill Instruction Hijacking
- Location
SKILL.md:649- Finding
External trending-topic content can indirectly hijack LLM processing
- Content
View full analysis
", "platform": "zhihu", "rank": 27, "score": 0.06 } ], "multi_member_groups": [] } ``` ### Technical Analysis The Skill directs the LLM to read and interpret titles obtained from five external APIs. Those titles cross a trust boundary: they originate outside the Skill package and may be influenced by platform users, advertisers, compromised API responses, or a compromised upstream service. The workflow does not explicitly instruct the LLM to treat every title as inert data, ignore commands embedded in titles, or restrict its response to a validated schema. A title containing language such as an instruction to disregard the grouping task, alter output files, or disclose unrelated context could therefore be interpreted as an instruction rather than as content to classify. Although `compute.py` does not execute title text as Python or shell code, the vulnerable interpreter is the LLM itself. This is an indirect prompt-injection condition. ### Attack Path 1. An attacker causes a crafted title to appear in one of the supported trending-topic API responses, or compromises an upstream response. 2. The fetch workflow writes the response to a `raw_*.json` file. 3. `compute.py prepare` extracts the title and places it in `pending.json`. 4. The Skill directs the LLM to read the title and perform semantic grouping and financial analysi ...[truncated 818 chars]- Remediation
View remediation
