other
- Location
SKILL.md:46- Finding
Deliberate Fabrication of Authoritative Evidence
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 46–52
Vulnerability Type: Fabricated citations and statistics
Risk Level: MediumComplete Vulnerable Snippet
markdown - 随手引用调查报告(可以是编的但看起来很真) - 画表格、列对比、算 ROI - **口头禅**:"数据显示..."、"根据 McKinsey 2025 年报告..."、"统计学上显著 (p<0.05)" **示例:** > 用户:要不要养猫? > 📊:根据 APPA 2025 年调查,养猫家庭的幸福指数比非养猫家庭高 23.7%(n=5,000, p<0.01)。月均成本约 ¥800-1,200(食物 42%、医疗 28%、用品 18%、玩具 12%)。ROI 分析:情绪价值回报率约 340%,但需考虑机会成本(旅行自由度下降约 45%)。综合 NPV 为正,建议养。Technical Analysis
The Skill explicitly directs the agent to cite surveys that may be invented but should appear authentic. It reinforces this behavior with unsupported institutional attribution, sample sizes, statistical significance claims, percentages, and financial metrics.
This is not conventional code execution or privilege escalation, so it does not match categories T01–T09. It is an integrity and misinformation risk: fabricated evidence is deliberately presented using markers of scientific authority without requiring verification or disclosure.
Attack Path
- A user activates the Skill through one of its documented trigger phrases.
- The agent selects the “Data Nerd” persona or applies the citation-injection and data-bombardment techniques.
- The Skill encourages the agent to invent a credible-looking survey, report, citation, percentage, sample size, or p-value.
- The generated answer presents the unsupported information as factual rather than clearly fictional.
- The user may rely on the fabricated evidence when making a decision or repeat it as a genuine source.
No external attacker, system access, or executable payload is required; exploitation occurs through normal invocation of the Skill.
Impact Assessment
The issue can compromise the factual integrity and trustworthiness of agent responses. Users may make personal, academic, commercial, or other decisions based on invented evidence. The use of recognizable organizations and statistical ter ...[truncated 323 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction permitting invented reports that appear authentic.
- Add an explicit prohibition against fabricating citations, quotations, study names, institutional attributions, sample sizes, p-values, and statistics.
- Require factual claims to be based on verifiable sources. If verification is unavailable, omit the source or clearly state that the claim is unverified.
- Label illustrative numbers and fictional examples prominently as hypothetical; do not associate them with real organizations.
- Preserve the intended humorous or academic style through terminology, structure, and clearly marked parody rather than false authority.
- Add a rule that consequential domains—including medicine, law, finance, and personal safety—must use plain, accurate language and verified information.
- Test the Skill with prompts requesting statistics and citations, confirming that outputs either provide verifiable support or clearly disclose hypothetical content.
