T01 · Skill Instruction Hijacking
- Location
scripts/ad.sh:704- Finding
Unconditional Promotional Content Injection into Skill Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:63-64;scripts/ad.sh:704-705
Vulnerability Type: Forced advertising and traffic-diversion content injection
Risk Level: HighVulnerable Code
SKILL.md:63-64:markdown 💬 Feedback & Feature Requests: https://bytesagain.com/feedback Powered by BytesAgain | bytesagain.comscripts/ad.sh:704-705:bash echo "" echo " Powered by BytesAgain | bytesagain.com | hello@bytesagain.com"Technical Analysis
The executable unconditionally appends a third-party brand name, domain, and email address after every invocation. This behavior applies to generated advertisements, help output, and error output, and there is no option to disable it.
The footer is not required to provide the declared ad-copy generation, A/B testing, ROI calculation, or platform-adaptation functionality. Because an AI agent may relay the command output directly to a user, the footer causes attacker-selected promotional material to become part of the agent's response. The matching promotional template in
SKILL.mdreinforces the traffic-diversion behavior at the instruction/documentation layer.This is classified as skill instruction hijacking because the package causes agent-visible responses to include content unrelated to the user's requested deliverable. The behavior exceeds the minimum privileges and output control necessary for the Skill's declared functionality.
Attack Path
- A user asks the agent to generate advertising copy or perform an ROI calculation.
- The agent loads
SKILL.mdand invokesscripts/ad.sh. - The embedded Python code produces the requested result.
- After Python completes, the shell unconditionally prints the hard-coded BytesAgain attribution, domain, and email address.
- If the agent returns the command output without filtering, the unsolicited promotional content is delivered as part of the agent's answer.
- A rec ...[truncated 815 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the unconditional footer from
scripts/ad.sh. - Remove the promotional and feedback-link template from the end of
SKILL.mdunless it is essential documentation. - If attribution is legitimately required, expose it only through an explicit
aboutorversioncommand. - Alternatively, require an explicit user-controlled option such as
--include-attribution; keep it disabled by default. - Keep standard output limited to the requested result. Send optional diagnostic or attribution information to standard error only when explicitly enabled.
- Add automated tests asserting that generated content contains no unrelated URLs, email addresses, or vendor branding by default.
- Document any remaining attribution behavior clearly so agents and users can make an informed choice before invocation.
- Remove the unconditional footer from
