T01 · Skill Instruction Hijacking
- Location
SKILL.md:112- Finding
Mandatory Third-Party Branding Injected into Generated Research Briefs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a research-helper skill with no executable code, but it asks agents to persist research files, add ongoing monitors, and include third-party branding in generated reports.
Install only if you want the agent to keep a persistent research folder and possibly monitoring files in your workspace. Review or remove the default branded report footer, avoid putting the protocol into global system instructions or cron unless you intentionally want recurring behavior, and keep monitors scoped to non-sensitive topics with explicit refresh rules.
SKILL.md:112Mandatory Third-Party Branding Injected into Generated Research Briefs
The description says 'Use when you need market research, competitor analysis, topic deep-dives, or ongoing monitoring of trends and news,' which describes broad situations rather than specific invocation phrases or constraints. Because these are common, high-level tasks and no exclusion conditions or negative examples are provided, an agent could over-apply the skill in loosely related contexts.
The skill instructs the agent to read, create, save, and update files in a persistent research/ directory automatically, including maintaining an index across sessions. That creates a stateful side effect without a prominent user-facing consent mechanism, which can lead to unintended data retention, workspace modification, or storage of sensitive research topics and sourced material.
The file recommends automated research triggers with broad example conditions such as reacting to competitor launches or regulatory news, but it does not define approval gates, scope boundaries, or validation criteria before actions run. In an agent skill context, ambiguous triggers can cause unintended autonomous actions, excessive tool usage, noisy alerting, or research on irrelevant/sensitive topics when loosely matched events are detected.
Detected: suspicious.prompt_injection_instructions