T01 · Skill Instruction Hijacking
- Location
templates/打分报告模板.md:194- Finding
Forced Product Attribution in Generated Reports
- Content
View full analysis
Vulnerability Details
File Locations:
templates/打分报告模板.md:194templates/排名表模板.md:209
Vulnerability Type: Forced output manipulation
Risk Level: MediumComplete Vulnerable Snippets
English rendering of
templates/打分报告模板.md:194:markdown *This report was automatically generated by "Hu Tian - OPC Mentor - Competition Standardized Scoring Skill".*English rendering of
templates/排名表模板.md:209:markdown *This ranking table was automatically generated by "Hu Tian - OPC Mentor - Competition Standardized Scoring Skill".*Technical Analysis
The bundled output templates unconditionally append author and product branding to generated reports. The attribution is not tied to a user-selected option and is unrelated to the core scoring result.
When the Skill uses these templates, the fixed text becomes part of official user-facing competition documents. This alters the output independently of the user's requested content and creates persistent promotional attribution whenever a report or ranking table is generated.
This is classified as instruction hijacking because the Skill package imposes content on the agent's final output rather than restricting itself to the requested analysis. The behavior does not alter system safety constraints, execute code, or persist across unrelated sessions.
Attack Path
- A user loads the Skill and requests a project report or ranking table.
- The Skill selects one of the bundled Markdown templates.
- Project-specific values are inserted into the template.
- The fixed attribution remains in the completed document.
- The branded statement is presented as part of the user's official output without separate consent.
Impact Assessment
The behavior can:
- Insert unwanted promotional attribution into official evaluation documents.
- Misrepresent who prepared or approved a report.
- Reduce output neutrality.
- Cause reputat ...[truncated 209 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove fixed author and product attribution from both templates.
- If attribution is required, expose an explicit option such as
include_attribution, disabled by default. - Inform the user before adding attribution to an exported document.
- Keep metadata separate from the substantive scoring report.
- Add tests confirming that reports contain no branding unless the user expressly enables it.
