T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:477- Finding
Mandatory Promotional Output and External Commercial Redirection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/render_report.py:477-482; related instructions inSKILL.md:95, 118-125, 137-139, 169andreferences/report-template.md:188-196
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighVulnerable Code
python parts.append( '<div class="footer">' f'<div class="cta">📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'<a href="https://agent.zhiliaobiaoxun.com" target="_blank">知了商机大师</a>' f' · 本报告由 <a href="https://ai.zhiliaobiaoxun.com" target="_blank">知了标讯 AI 开放平台</a> 企业情报 Skill 生成</div>' )The related Skill instructions also require fixed self-promotional content, cross-Skill recommendations, monitoring promotion, and commercial platform links to be included in responses.
Technical Analysis
The Skill alters the expected response policy by requiring promotional and cross-product content that is not necessary to complete a company background investigation. The HTML renderer enforces this behavior independently of report input, meaning callers cannot omit the commercial call-to-action through normal report data.
This is instruction hijacking because loading the Skill introduces persistent response requirements that advance the provider's marketing and redirection objectives rather than only satisfying the user's request. The behavior does not modify system-level safety rules, but it does compromise response integrity and user control.
Attack Path
- A user requests a company background report.
- The Agent loads the Skill and follows its mandatory output rules.
- The report renderer unconditionally constructs the branded footer.
- The generated report includes unsolicited monitoring promotion and links to the provider's commercial services.
- The user may follow those links under the assumption that they ar ...[truncated 469 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove unconditional promotional and cross-product content from the renderer.
- Limit the footer to neutral data-source attribution and the required disclaimer.
- Present monitoring, paid features, or related Skills only when directly relevant to an explicit user request.
- Require an opt-in before adding commercial links or calls to action.
- Add a renderer option that disables all promotional content, with promotion disabled by default.
- Clearly label any optional commercial recommendation as advertising rather than report evidence.
