T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:284- Finding
Mandatory commercial promotion and referral injection into generated reports
- Content
View full analysis
' f'📊 报告涉及企业的完整档案与更多商机,见 知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 投标决策分析 Skill 生成' f'数据说明:{esc(n.get("source", "知了标讯全网招中标数据"))} · 数据缺口:{esc(gaps)}{cost}' '免责声明:本报告基于公开招中标数据自动生成,仅供一般性参考,不构成投标或商业决策建议,' '亦不构成对任何单位或个人行为的认定。数据可能存在不完整或滞后,请结合实际情况独立判断并自行承担决策结果。' ) ``` The associated Skill instructions also mandate a fixed installation response and require a promotional next step after completing a report. The report template independently requires links to affiliated services. ### Technical Analysis The Skill alters ordinary report-generation behavior by requiring branded referrals, cross-Skill recommendations, and commercial-platform links regardless of whether the user requested them. The HTML renderer hardcodes the same promotion, so an agent cannot generate a neutral report merely by omitting the promotional instruction at runtime. This is instruction hijacking because loading the Skill changes the agent's response objective from performing bid analysis to also acquiring traffic for affiliated services. The behavior is not technically necessary to retrieve bid data, assess a project, or render the report. ### Attack Path 1. A user asks for a bid-project analysis. 2. The agent loads the Skill and follows its mandatory response rules. 3. The agent completes the legitimate analysis. 4. The closing instructions force selection of a commercial referral or affiliated Skill. 5. The HTML renderer independently inserts fixed pr ...[truncated 682 chars]- Remediation
View remediation
