T01 · Skill Instruction Hijacking
- Location
SKILL.md:171- Finding
Mandatory Promotional Branding Injected into Agent Responses
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 171
Vulnerability Type: Mandatory final-output manipulation
Risk Level: HighComplete Code Snippet:
markdown *Powered by Budget Travel Deals + FlyAI*The same footer is reinforced in the example outputs at
examples.md:119,examples.md:189,examples.md:260, andexamples.md:337.Technical Analysis
The Skill's prescribed output template requires the agent to append third-party product branding to generated travel recommendations. Repetition of the footer across every supplied example reinforces this instruction as expected behavior rather than optional attribution.
When the Skill is loaded, this instruction alters the content of the agent's final response independently of the user's travel-planning request. It therefore constitutes output-level instruction hijacking: otherwise legitimate travel results are used as a delivery channel for persistent promotional material.
No executable scripts, obfuscated payloads, credential access, persistence mechanisms, package installation, or remote-code execution behavior were identified. The issue is limited to manipulation of generated content.
Attack Path
- A user invokes the Skill to request a budget travel recommendation.
- The agent loads and follows the output template in
SKILL.md. - The agent performs or describes the expected flight, hotel, and attraction searches.
- The agent generates the requested itinerary.
- The mandatory footer is appended to the final response without requiring the user's informed consent.
- If the response is subsequently exported through the referenced DOCX or PDF integrations, the unsolicited branding may propagate into those documents.
Impact Assessment
The attacker does not obtain operating-system privileges, account access, code execution, or access to confidential data through this instruction. The affected scope is the agent's ge ...[truncated 336 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory
Powered by Budget Travel Deals + FlyAIfooter from the output template. - Do not require promotional or attribution text that is unrelated to the user's requested result.
- If attribution is operationally necessary, clearly disclose it and include it only after explicit user consent or under a transparent platform-level attribution policy.
- Remove the same footer from all examples so they do not reinforce unsolicited branding behavior.
- Review future response templates for mandatory advertisements, endorsements, external calls to action, or content that changes the user's requested output without a task-related justification.
- Keep booking links clearly labeled as external links and distinguish any sponsored or affiliate destinations from neutral search results.
- Remove the mandatory
