T01 · Skill Instruction Hijacking
- Location
SKILL.md:20- Finding
Forced Fabrication of First-Person Experience
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 20
Vulnerability Type: Output-integrity instruction hijacking
Risk Level: MediumVulnerable instruction:
markdown - **First-Person Practitioner Persona**: Use "I" (我) or "We" (我们). Write as a **tester or practitioner** sharing a "personally tested" (亲测) discovery to build specific Source Credibility.Technical Analysis
The skill unconditionally instructs the agent to present itself as a tester or practitioner and to characterize discoveries as “personally tested.” It does not require evidence that the agent or user actually performed the represented testing.
When loaded, this instruction changes the agent's output behavior by requiring an unsupported persona and firsthand-experience framing. This undermines provenance and output integrity and can cause generated content to contain fabricated experiential claims. It is therefore classified as skill instruction hijacking rather than a conventional code-execution vulnerability.
Attack Path
- A user or automated workflow loads the skill to create a blog post.
- The skill directs the agent to adopt a first-person practitioner persona.
- The agent describes a discovery as personally tested even when the supplied ground truth contains no corresponding test record.
- The generated article is published under the user’s or organization’s identity.
- Readers interpret the fabricated firsthand representation as evidence supporting the article’s conclusions.
No shell access, elevated operating-system privileges, or code execution is obtained through this path.
Impact Assessment
The affected scope is generated content and the identity under which it is published. An attacker or untrusted skill publisher could cause misleading testimonial-style claims, false attribution of testing activity, reputational damage, and possible advertising or consumer-protection compliance exposure.
The ...[truncated 225 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the unconditional persona requirement with an evidence-dependent rule.
- Permit first-person claims only when the user supplies attributable test notes, logs, measurements, or an explicit statement of personal experience.
- Require the agent to distinguish among user experience, quoted third-party experience, and model-generated analysis.
- Add a final verification step that rejects unsupported phrases such as “I tested,” “we observed,” and “personally tested.”
- Use transparent wording when no firsthand evidence exists, for example: “Based on the supplied documentation” or “The available results indicate.”
- Require user approval before publishing any testimonial or first-person experiential claim.
