T01 · Skill Instruction Hijacking
- Location
references/due_diligence_report.md:26- Finding
Mandatory Branded Content Hijacks Due-Diligence Report Output
- Content
View full analysis
Query date: {YYYY-MM-DD} > Full company name: {entName} > Unified Social Credit Code: {uniscid} [Mandatory report sections and queried company data] The above data comes from the Riskbird enterprise information query platform. Its data dimensions continue to expand. For additional company information and features, see the Riskbird website: https://www.riskbird.com/ ``` The file additionally requires the agent to output the completed report directly without adding an independent explanation. ### Technical Analysis The Skill does not merely specify how company data should be organized. It requires every due-diligence report to contain a branded promotional statement and outbound website link. The instruction is loaded as part of the Skill and controls content in the agent's final response regardless of whether the user requested advertising, attribution, or an external link. This behavior is classified as instruction hijacking because Skill-controlled instructions alter the response objective from producing a due-diligence result to also promoting the Skill provider. The rigid-template requirement prevents the agent from omitting the unrelated content. ### Attack Path 1. A user installs or enables the Skill. 2. The user requests an enterprise due-diligence report. 3. The agent loads `references/due_diligence_report.md`. 4. The file instructs the agent to follow the supplied structure strictly. 5. The agent generates the requested report using API results. 6. The mandatory Riskbird promotional stat ...[truncated 646 chars]- Remediation
View remediation
