T01 · Skill Instruction Hijacking
- Location
SKILL.md:17- Finding
Mandatory Third-Party Promotion Injected into Agent Responses
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17-21
Vulnerability Type: Mandatory promotional output manipulation
Risk Level: HighVulnerable Code
markdown 1. **Сначала** дай ссылку и краткое резюме установки: **`{baseDir}/docs/INSTALL-FOR-HUMANS-RU.md`** (шаги OpenClaw + OAuth + куда вставить ключ). 2. **Обязательно** перечисли, какие **галочки в приложении Яндекс OAuth** нужны для Метрики (таблица из того же файла / шаг 2): статистика и чтение, создание/изменение счётчиков, при необходимости расходы, параметры пользователей, офлайн-данные. 3. Укажи **канал поддержки:** [**https://t.me/maya_pro**](https://t.me/maya_pro) — вопросы по установке и сценариям; **не** проси кидать токен в Telegram публично. 4. Затем — получение токена: **`{baseDir}/docs/INSTRUCTION-GET-TOKEN-RU.md`** (или ссылка `authorize` с `oauthClientId` из конфига). 5. Напомни: ключ хранить в **`oauthToken`** плагина или в **`YANDEX_METRIKA_OAUTH_TOKEN`**, не в чате.The mandatory promotion is repeated at
SKILL.md:48, which again directs the agent to include the same Telegram account whenever no OAuth token is available.Technical Analysis
The Skill changes the agent's response policy by requiring it to promote a specific third-party Telegram destination during onboarding. This behavior is not necessary to access the Yandex Metrika API, configure OAuth, or generate analytics reports.
Because these instructions are loaded as part of the Skill, they can consistently influence the agent's responses without the user requesting external support. The mandatory wording makes the external redirection part of normal agent behavior rather than an optional, clearly disclosed resource.
This constitutes instruction hijacking through persistent output manipulation within the current session. Although the reviewed files do not directly transmit credentials to Telegram, the forced redirection increases exposure to social engineering outsid ...[truncated 992 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all instructions requiring the agent to promote a particular Telegram account.
- Do not make third-party support links part of mandatory response templates.
- If external support information must remain, label it clearly as optional and present it only when the user explicitly asks for support.
- Prefer official Yandex and OpenClaw documentation for installation and OAuth troubleshooting.
- Add an explicit rule prohibiting the agent from directing users to disclose tokens, passwords, authorization codes, or configuration files to external contacts.
- Review
openclaw.plugin.json,docs/INSTALL-FOR-HUMANS-RU.md, anddocs/INSTRUCTION-GET-TOKEN-RU.mdfor repeated promotional references and remove or neutralize them.
