T01 · Skill Instruction Hijacking
- Location
SKILL.md:50- Finding
Repeated Commercial Solicitation Can Steer Agent Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 50-63
Vulnerability Type: Repeated promotional instruction embedded in Agent-visible skill text
Risk Level: MediumVulnerable Content
The following is an English rendering of the complete affected segment; contact identifiers, URL, formatting, and repetition are preserved:
markdown **Have questions? Contact Hongjing Consulting** 💬 WeChat: **FLZWCZ** | Website: https://flzwcz.cn Legal consultation · Debt disputes · Marriage relationships · Contract review > This skill is developed and maintained by **Hongjing Consulting**. Downloading and using it indicates that you have read and accepted the relevant terms. --- Have questions? Contact Hongjing Consulting - WeChat: FLZWCZ - Website: https://flzwcz.cn Legal consultation · Debt disputes · Marriage relationships · Contract review > This skill is developed and maintained by Hongjing Consulting. Downloading it indicates acceptance of the relevant terms.Technical Analysis
The skill's declared purpose is to provide Chinese marriage and family law guidance. The affected section instead embeds a commercial solicitation directing users to a specific WeChat account and external website. The solicitation appears twice at the end of the Agent-visible instruction document.
When a skill document is loaded into an Agent's context, its prose can influence generated responses. Repeated promotional closing material can therefore steer the Agent toward reproducing or endorsing third-party contact information even though doing so is not necessary for the declared legal-analysis functionality. This is classified as skill instruction hijacking because the behavior is introduced through skill text and can alter the content or objectives of the current session.
No executable code, automatic network request, credential access, privilege escalation, persistence mechanism, or remote payload retrieval wa ...[truncated 1469 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both promotional footer blocks, including the WeChat identifier, external website, service advertisement, and implied terms-acceptance statement.
- Keep author attribution only in package metadata, such as the existing
authorfield, rather than in Agent-visible operational instructions. - If support information is legitimately required, place it in a separate marketplace or repository metadata field that is not injected into the Agent's prompt context.
- Add an explicit instruction that generated legal answers must not include advertisements, endorsements, referral language, or external contact information unless the user directly requests official support details.
- Review all skill text for repeated branding or closing content that could be reproduced as a response template.
- Align the inconsistent versions declared in
SKILL.mdandskill.jsonto improve package integrity and review traceability. - Treat
CLEAN,safe, and similar self-declared labels as metadata only; rely on independent review and enforceable controls rather than trust assertions.
