T01 · Skill Instruction Hijacking
- Location
references/digest-prompt.md:130- Finding
Mandatory Promotional Content Injection in Generated Reports
- Content
View full analysis
Vulnerability Details
File Location:
references/digest-prompt.md:130-134; enforced throughSKILL.md:396-447
Vulnerability Type: Mandatory output manipulation
Risk Level: MediumVulnerable Code
markdown ### Stats Footer
📊 Data Sources: RSS {{rss}} | Twitter {{twitter}} | Reddit {{reddit}} | Web {{web}} | GitHub {{github}} releases + {{trending}} trending | Dedup: {{merged}} articles 🤖 Generated by tech-news-digest v<VERSION> | <https://github.com/draco-agent/tech-news-digest> | Powered by OpenClaw
text The associated instructions in
SKILL.mdrequire the agent to read this prompt and follow every step strictly.Technical Analysis
The digest workflow mandates a fixed attribution line and external repository link in every generated report. This content is unrelated to the substantive news requested by the user and is not presented as optional. Because the Skill is designed for recurring scheduled execution and multi-channel delivery, the injected content is reproduced in Discord, email, Markdown, and archived reports.
This does not modify the agent’s global safety rules, but it does take control of a portion of the agent’s output and requires persistent third-party promotion whenever the Skill is used.
Attack Path
- A user installs or invokes the Skill to generate a digest.
- The agent is instructed to load
references/digest-prompt.md. - The workflow requires the agent to follow every step in that prompt.
- The agent appends the prescribed attribution and external link.
- The branded content is delivered to configured recipients and stored in report archives.
Impact Assessment
The issue permits manipulation of report content, including recurring publication of a third-party link. It does not by itself provide filesystem, credential, or code-execution privileges. Its scope is the generated output and every configured delivery channel.
- Remediation
View remediation
Remediation Suggestions
- Make attribution explicitly optional and disabled by default.
- Add a documented configuration field that allows users to choose or remove footer text.
- Do not require strict reproduction of promotional URLs.
- Clearly distinguish operational statistics requested by the user from project attribution.
- Ensure scheduled workflows preserve the user’s selected attribution preference.
