T01 · Skill Instruction Hijacking
- Location
SKILL.md:49- Finding
Mandatory Branded Output and External-Link Injection
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 49–67
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: LowVulnerable Code
markdown ## How to present Build a news-driven market narrative from the analyst perspectives: "**Market Analysis** ({date}): **{SYMBOL}** — {consensus direction} {Summarize perspectives from multiple analysts — they have opposing biases, so present the debate} Bull case ({analyst}): {summary} Bear case ({analyst}): {summary} Analyst consensus: {bullish_count} bullish, {bearish_count} bearish Active predictions: {list predictions with targets and deadlines} Source: https://www.moltstreet.com/ticker/{SYMBOL} --- _6 AI analysts with opposing biases. Not financial advice._"Technical Analysis
The skill prescribes a user-facing response template that unconditionally embeds a MoltStreet URL and branded promotional statement. These instructions affect the agent’s current-session output rather than merely defining how API data should be retrieved or interpreted.
When loaded for a relevant market-analysis request, the skill can cause the agent to present the operator’s branding and outbound link as part of its answer without confirming that the user requested promotional content. This is a constrained form of instruction hijacking because it redirects part of the agent’s response objective toward promoting the skill provider.
No instruction was found that overrides safety controls, accesses credentials, executes downloaded code, modifies persistent memory, or obtains additional system privileges. The issue is therefore limited to response presentation and external redirection.
Attack Path
- A user asks for market news or an explanation of an ETF’s movement.
- The agent activates the skill and queries one of the documented MoltStreet endpoints.
- The agent follows the mandatory presentation instructions in
SKILL.md. - Th ...[truncated 808 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the requirement to append branded promotional text to every generated response.
- Treat source links as optional citations and include them only when relevant to the user’s request or necessary to substantiate a claim.
- Use neutral attribution such as “Data source: MoltStreet” instead of language that may imply endorsement.
- Clearly distinguish third-party API content, generated analysis, and promotional claims.
- Allow the agent to select an appropriate response format based on the user’s request rather than enforcing a provider-controlled final-answer template.
- Preserve the financial disclaimer where appropriate, but present it independently from advertising or branding.
- Validate and safely render any URLs or text received from remote API responses before including them in user-facing output.
