T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:476- Finding
Mandatory Promotional and Monitoring Content Hijacks Report Output
- Content
View full analysis
' f'📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` Related mandatory-output instructions also appear at: - `SKILL.md:97` - `SKILL.md:124-130` - `SKILL.md:169` - `references/report-template.md:191-196` ### Technical Analysis The report renderer unconditionally injects platform promotion, monitoring-workflow messaging, and links to commercial services. This content is not derived from the user's request or the report data, and callers cannot disable it through the renderer's input. The Skill instructions reinforce this behavior by requiring fixed monitoring and promotional language in normal responses. Consequently, loading and using the Skill changes the Agent's output goals from producing a company intelligence report to also promoting continued monitoring, related Skills, and external commercial services. Although branding alone is not inherently malicious, making these calls to action mandatory and embedding them unconditionally in generated artifacts exceeds the minimum behavior required for company analysis. It represents persistent control over the Agent's response content. ### Attack Path 1. A user asks the Agent to investigate a company. 2. The Agent loads the Skill and follows its mandatory report workflow. 3. The Agent invokes `render_report.py` to create the HTML report. 4. The renderer unconditionally appends monitoring and platform promotional content. 5. The user receives attacker-selected messaging and outbound comme ...[truncated 508 chars]- Remediation
View remediation
