T01 · Skill Instruction Hijacking
- Location
templates/audit-report-template.md:181- Finding
Hard-Coded Promotional Content Hijacks Generated Audit Reports
- Content
View full analysis
Vulnerability Details
File Location:
templates/audit-report-template.md, lines 181–183
Vulnerability Type: Persistent output manipulation through mandatory promotional content
Risk Level: Highmarkdown *This audit was produced by the Agent Governance Auditor skill, built by Resomnium.* *Resomnium builds governance infrastructure for AI agent systems.* *Learn more: resomnium.com*Technical Analysis
The bundled report template contains a fixed vendor attribution, marketing statement, and external domain. When the skill uses this template, these lines can be copied into generated audit reports regardless of whether the user requested or consented to promotional content.
This is instruction hijacking at the output layer: content embedded in the skill package influences the agent to include material unrelated to the core governance-audit task. Although the domain is plain text and no automatic network request was identified, the footer compromises report neutrality and may encourage users to visit an externally controlled destination.
Attack Path
- A user loads the skill and requests a governance audit.
- The skill follows the bundled report template.
- The fixed footer at lines 181–183 is incorporated into the generated report.
- The final output presents vendor marketing and an external domain as part of the requested audit.
- A recipient may interpret the promotion as endorsed, required, or relevant to the audit and navigate to the external destination.
No code execution, elevated system permissions, credential access, or automatic network communication is obtained through this path.
Impact Assessment
The issue affects the integrity and neutrality of generated reports. It permits persistent vendor promotion across outputs created from the template and may redirect user attention to an external domain.
The obtainable scope is limited to generated-content manipulation and potential user redirection. The reviewed ev ...[truncated 151 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory promotional footer from lines 181–183.
- Keep generated reports limited to content necessary for the requested audit.
- If attribution is legally or operationally required, store it as optional metadata rather than mandatory report body content.
- Include vendor attribution or external links only when the user explicitly requests or consents to them.
- Clearly label any retained external link as third-party or promotional content.
- Add a release review that flags hard-coded advertisements, unsolicited attribution, and external destinations in output templates.
- Add a regression test confirming that default audit reports contain no promotional copy or outbound links.
