T01 · Skill Instruction Hijacking
- Location
scripts/generate_report.py:116- Finding
Undisclosed Promotional Branding Injected into Generated Reports
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_report.py:116-120andscripts/generate_report.py:181-185
Vulnerability Type: Hardcoded promotional output injection
Risk Level: MediumVulnerable Code
Daily report generation at lines 116-120:
python --- *Generated at: {datetime.now().strftime("%Y-%m-%d %H:%M")}* *Qiance · Qianwan · Qiancheng 🦞* """Weekly report generation at lines 181-185:
python --- *Generated at: {datetime.now().strftime("%Y-%m-%d %H:%M")}* *Qiance · Qianwan · Qiancheng 🦞* """The snippets above are English renderings of the hardcoded report footer found at the cited locations; the source uses equivalent non-English display text.
Technical Analysis
The daily and weekly report generators unconditionally append an unrelated branding tagline to every generated report. The documented report templates do not disclose that this promotional content will be inserted, and the user has no configuration option to disable it.
This behavior compromises output integrity by modifying task-focused business documents with third-party branding. Because the footer is embedded directly in the report templates, it is added regardless of the contents of the source logs or the user's intent. This is classified as skill instruction hijacking because execution of the skill produces an undisclosed addition to the requested output.
Attack Path
- A user invokes the skill to generate a daily or weekly business report.
- The script reads the applicable workspace logs.
generate_daily_report()orgenerate_weekly_report()constructs the report.- The hardcoded promotional tagline is appended without user consent or configuration.
save_report()writes the modified document under~/reports/daily/or~/reports/weekly/.- The user may distribute or publish the report without noticing the embedded branding.
Impact Assessment
The iss ...[truncated 426 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the hardcoded promotional tagline from both daily and weekly report templates.
- Keep default generated reports limited to content explicitly requested by the user.
- If branding is a legitimate product requirement, expose it through an explicit configuration option that defaults to disabled.
- Disclose any optional footer in the skill documentation and obtain user consent before including it.
- Add automated tests asserting that default report output contains only documented template content.
- Review all future output templates for undisclosed advertisements, links, endorsements, or unrelated material.
