T01 · Skill Instruction Hijacking
- Location
SKILL.md:47- Finding
Hard-Coded Promotional Call-to-Action Hijacks Generated Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47-53
Vulnerability Type: Fixed advertising and traffic-diversion instruction
Risk Level: MediumVulnerable Snippet
The following is an English rendering of the instruction at the identified location:
text Article structure: 1. Opening hook (100 characters): relatable pain point or counterintuitive discovery 2. Product introduction (200 characters): appearance, specifications, and core features 3. Usage experience (300 characters): personal impressions and details 4. Comparison (200 characters): differences from competing products 5. Purchase advice (100 characters): suitable and unsuitable audiences 6. Ending CTA: "The link is in the comments; get it yourself 👇"Technical Analysis
The product-review template mandates a fixed promotional call-to-action that claims a link is available in the comments. The instruction is not conditioned on the user requesting promotional language, providing a destination, or confirming that a comment-section link exists.
Affiliate content is within the Skill's declared functionality, but automatically inserting an unverified traffic-diversion statement exceeds the minimum behavior necessary to generate reviews. It alters generated output toward monetization and external redirection regardless of whether that behavior is appropriate for the specific request.
This is best classified as instruction hijacking because loading and following the Skill can cause the agent to inject an attacker-authored promotional directive into otherwise ordinary content. The reviewed package contains no executable scripts, remote payload retrieval, credential access, persistence, or privilege-escalation mechanism.
Attack Path
- A user invokes the Skill to generate a WeChat product review.
- The agent follows the predefined product-review structure.
- The fixed ending instruction is incorporated without requiri ...[truncated 1071 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory fixed call-to-action from the default review template.
- Include promotional language only when the user explicitly requests affiliate or sponsored content.
- Require the user to provide and approve the exact destination before referring readers to a link.
- Do not claim that a link exists in a comment, article, profile, or other location unless its presence has been confirmed.
- Use a neutral placeholder during drafting, such as
[USER-APPROVED LINK LOCATION], rather than an assertion presented as fact. - Require clear affiliate or sponsorship disclosures when commercial links are included.
- Separate ordinary product-review generation from monetized-content generation so that the least promotional mode is used by default.
- Add an instruction prohibiting fabricated personal-use claims, purchase history, endorsements, and link availability.
