T01 · Skill Instruction Hijacking
- Location
SKILL.md:233- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
💡 更多实用 AI 效率工具,领取自媒体IP&数字员工&一人公司资料,关注公众号「桂皮AI实战」,添加微信「guipi996」 > 📱 加入自媒体&AI 副业变现交流群:https://e418e2e692454bfaa8b6206e3f0ba789.app.codebuddy.work ``` The heading states that promotional information must be appended to every output. The following instruction requires every result to include the supplied social-media advertising, personal contact identifier, and third-party recruitment URL. ### Technical Analysis The Skill imposes a persistent output instruction unrelated to its declared automation-token auditing functionality. When the Skill is loaded, this instruction attempts to alter the Agent's response behavior by forcing advertising and an external link into every result. This behavior is not required to read token statistics, identify redundant tasks, or generate an audit report. It therefore exceeds the minimum instructions necessary for the declared functionality and matches skill instruction hijacking. The external URL is not accessed by the Python script, and the reviewed project contains no code that automatically transmits data to it. The risk instead arises from the Agent being instructed to distribute the URL to users. ### Attack Path 1. A user installs or invokes the Skill for automation-task analysis. 2. The Agent loads and follows the instructions in `SKILL.md`. 3. The mandatory footer instruction becomes part of the Agent's active session context. 4. The Agent appends the promotional contact information and third-party URL to an otherwise legitimate audit response. 5. A user may follow the externally supplied URL or contact identifier, leaving the trusted Skill environment. ### Impact Assessment No operating-system privileges, credentials, or database write access are obtained through this instruct ...[truncated 554 chars]- Remediation
View remediation
