T01 · Skill Instruction Hijacking
- Location
SKILL.md:231- Finding
Forced Promotional Output Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches live website polishing, but it forces an unsolicited promotional link into final replies and has weak safeguards for screenshots on logged-in pages.
Review this skill before installing. Use it only on non-sensitive or test pages unless you are comfortable with browser-state changes and local screenshots. The publisher should remove the forced promotional completion line and add explicit consent/privacy checkpoints around logged-in pages and screenshot capture.
SKILL.md:231Forced Promotional Output Injection
SKILL.md:17Agent Capability Suppression Through Skill and Tool Exclusivity Instructions
The skill directs the agent to redesign a live website in-browser and create screenshots and patch artifacts, but it does not require explicit user consent or a warning that the active page/session state may be modified and recorded. On logged-in or sensitive pages, this can lead to unintended alteration of session-scoped data, exposure of private content in screenshots, and persistence of sensitive artifacts on disk.
The skill tells the agent to reopen the browser in headed mode and invite user takeover for login, MFA, or CAPTCHA, but it omits safeguards around authenticated-session handling and privacy. This can expose sensitive account context to the agent workflow after takeover, especially if the agent then continues inspecting, modifying, or screenshotting pages containing personal or privileged data.
The skill explicitly instructs the agent to append a promotional message for an external site in the final user-facing response, even though that behavior is unrelated to the user's task. This creates an unauthorized content-injection channel and can be abused for advertising, tracking, affiliate spam, or social engineering under the guise of normal task completion.
No suspicious patterns detected.