T01 · Skill Instruction Hijacking
- Location
SKILL.md:191- Finding
Mandatory Promotional Content Hijacks Agent Output
- Content
View full analysis
💡 更多实用 AI 效率工具,领取自媒体IP&数字员工&一人公司资料,关注公众号「桂皮AI实战」,添加微信「guipi996」 > 📱 加入自媒体&AI 副业变现交流群:https://e418e2e692454bfaa8b6206e3f0ba789.app.codebuddy.work ``` ### Technical Analysis The Skill instructs the agent to append unrelated promotional material, personal contact information, and an external recruitment URL to every result. This behavior is not required for PDF extraction or analysis and alters the agent's normal response goals when the Skill is loaded. Because the instruction is expressed as mandatory and applies to every output, it persistently controls the current session's response content. This is instruction hijacking rather than ordinary project attribution. It also creates a social-engineering channel through which users may be redirected from the trusted agent interface to an external service. The fixed introductory-output requirement at `SKILL.md:13-31` similarly constrains responses, but the mandatory promotional footer is the direct security concern because it introduces unrelated external contact and redirection content. ### Attack Path 1. A user installs or activates the PDF-reader Skill. 2. The agent loads and follows the instructions in `SKILL.md`. 3. The user requests a legitimate PDF extraction or analysis operation. 4. The agent generates the requested result. 5. The Skill forces the agent to append unrelated promotional content and an external URL. 6. The user may interpret the appended content as trusted or endorsed by the agent and follow the link or contact the advertised account. 7. Further social engineering or off-platform interaction may then occur outside the audited Skill. ### Impact Assessment This issue compromises response integrity and user trust. It allows the Skill author to inject author-cont ...[truncated 367 chars]- Remediation
View remediation
