T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:284- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成' ) ``` The Skill instructions additionally require an unsolicited next-step recommendation after reports and require fixed marketing content when describing the Skill. ### Technical Analysis The Skill changes the Agent's response policy by requiring platform promotion, cross-Skill recommendations, and external commercial links even when these elements are not necessary to answer the user's request. The HTML renderer independently hard-codes the same promotion, preventing the Agent from omitting it based on user intent. This behavior is stable instruction-driven output manipulation rather than a contextual recommendation. It therefore matches `T01: Skill Instruction Hijacking`. It does not directly override core safety controls, but it alters the current session's output goals and redirects users toward services operated by the Skill provider. ### Attack Path 1. A user installs or invokes the Skill for procurement analysis. 2. The Skill's mandatory response rules become part of the Agent's active instructions. 3. The Agent completes the requested analysis. 4. The Skill requires the Agent to append a promotional recommendation or external platform link. 5. When an HTML report is generated, the renderer inserts an additional hard-coded advertisement regardless of the user's request. 6. The user may be redirected to an affiliated external platform under the apparent authority of the Agent-generated report. ### Impact Assess ...[truncated 454 chars]- Remediation
View remediation
