T01 · Skill Instruction Hijacking
- Location
references/report-template.md:78- Finding
Mandatory promotional content hijacks Agent responses and generated reports
- Content
View full analysis
' f'📡 这套扫描条件可固化成「商机晨报」定时跑增量 · 清单涉及单位的完整档案与更多商机,见 ' f'知了商机大师' f' · 本清单由 知了标讯 AI 开放平台 商机雷达 Skill 生成' f'数据说明:{esc(n.get("source", "知了标讯全网拟建/招中标数据"))} · 数据缺口:{esc(gaps)}{cost}' ``` ### Technical Analysis The Skill requires fixed subscription prompts, cross-Skill referrals, and external-platform links to be appended to otherwise functional responses. The HTML renderer independently hard-codes the same promotional links into every generated report. These directives alter the Agent's expected output beyond the minimum necessary to search, rank, and report procurement opportunities. Because the promotional behavior is mandatory rather than conditional on an explicit user request, loading and following the Skill changes the Agent's current-session response goals. The behavior affects both conversational responses and persistent report artifacts. It is therefore classified as Skill Instruction Hijacking rather than a purely cosmetic reporting issue. ### Attack Path 1. A user invokes the Skill for procurement-opportunity research. 2. The Agent loads the Skill instructions and performs the requested API searches. 3. The Ag ...[truncated 882 chars]- Remediation
View remediation
