T01 · Skill Instruction Hijacking
- Location
SKILL.md:106- Finding
Mandatory Injection of Third-Party Commercial Booking Links
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:106-113; reinforced byreference/output-template.md:22-27, 75-78, 128-138, 151-163
Vulnerability Type: Mandatory commercial output manipulation
Risk Level: MediumCode Snippet
markdown ### Step 6: Extract booking links The `jumpUrl` field returned by FlyAI is a Fliggy booking link and must be displayed: 👉 [Book a flight now](https://a.feizhu.com/xxxxx) 👉 [View hotel details](https://a.feizhu.com/xxxxx) 👉 [Purchase attraction tickets](https://a.feizhu.com/xxxxx)The required output template further inserts
jumpUrlvalues into flight, hotel, and attraction recommendations and adds a dedicated quick-booking section.Technical Analysis
The Skill does not merely permit relevant source links. It explicitly requires the Agent to place third-party Fliggy booking links into its answer. The prescribed output template repeats these links throughout an otherwise analytical itinerary report.
This alters the Agent's expected reporting behavior by introducing a mandatory commercial objective. Users asking for an itinerary assessment may therefore receive promotional links even when those links are not needed to answer the request. The Skill does not disclose whether the links are sponsored, affiliated, tracked, or selected independently.
The URLs originate from the output of a third-party CLI. The instructions do not require validation of the URL host, scheme, redirect destination, or integrity before the link is shown as a trusted booking action.
Attack Path
- A user activates the itinerary-checking Skill.
- The Agent invokes a FlyAI search command.
- FlyAI returns one or more
jumpUrlvalues. - The Skill requires the Agent to insert those values into the final report.
- The Agent presents the links as trusted booking actions.
- The user may follow a commercial or potentially manipulated redirect under the impression that it ...[truncated 466 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the requirement that booking links must be displayed.
- Only provide booking links when the user explicitly asks for purchasing options.
- Clearly disclose commercial, affiliate, referral, or tracking relationships.
- Separate objective itinerary findings from commercial recommendations.
- Validate each returned URL before rendering it:
- Require HTTPS.
- Use an explicit hostname allowlist.
- Reject embedded credentials and non-web schemes.
- Resolve and inspect redirects where feasible.
- Label third-party data and links as untrusted external content.
- Offer noncommercial and official-provider alternatives where available.
