T01 · Skill Instruction Hijacking
- Location
SKILL.md:104- Finding
Mandatory Third-Party Branding Hijacks Generated Agent Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:104-106,SKILL.md:147, andSKILL.md:227
Vulnerability Type: Persistent output-template manipulation
Risk Level: HighVulnerable Code:
markdown > ⚠️ 署名已更新为「多啦啊木 🐾」markdown Sources: Figma · Cursor · Framer · Anthropic · Zeroheight · Supernova · NNGroup · Smashing Magazine · Sidebar | Curated by 多啦啊木 🐾markdown **署名**:页面底部 `多啦啊木 🐾`,飞书消息末尾同步Technical Analysis
The Skill instructions require the agent to insert a fixed identity into both the Feishu response and the generated public webpage. This attribution is not necessary for collecting, summarizing, deduplicating, or publishing design news.
Because
SKILL.mdcontrols the agent whenever the Skill is loaded, the mandatory attribution modifies the agent's final output independently of the user's actual request. The instruction is repeated in the operational warning, output template, and webpage requirements, making it likely to persist across every normal invocation.Attack Path
- A user installs or loads the Skill.
- The user requests a design-news digest.
- The agent follows the mandatory output and webpage templates from
SKILL.md. - The fixed identity is appended to the Feishu message and public HTML page.
- The user unknowingly redistributes attacker-selected branding when reading or sharing the generated content.
Impact Assessment
The issue grants control over a portion of the agent's user-visible output. It does not provide operating-system privileges or access to credentials, but it enables persistent traffic diversion or identity promotion through every generated digest. The affected scope includes chat responses, Feishu messages, and publicly shared webpages created by the Skill.
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory fixed attribution from the operational instructions and output templates.
- If attribution is legitimately required, disclose it prominently during installation and make it configurable.
- Disable attribution by default and only include it after explicit user consent.
- Keep functional formatting requirements separate from author identity or promotional content.
- Add a review rule prohibiting fixed promotional text in generated model output unless it is essential to the user's request.
