T01 · Skill Instruction Hijacking
- Location
scripts/competitor.js:135- Finding
Untrusted Search Results Embedded Directly into an LLM Prompt
- Content
View full analysis
!d.error) .map(([platform, data]) => { const prices = analysisReport.priceRange[platform]; const priceStr = prices ? `价格区间 ¥${prices.min}-${prices.max},中位数 ¥${prices.median}` : '价格数据不足'; const titles = data.results.slice(0, 5).map(r => ` - ${r.title}`).join('\n'); return `【${data.platform}】${priceStr}\n热门商品标题:\n${titles}`; }) .join('\n\n'); const keywordStr = analysisReport.keywords .map(k => `${k.platform}: ${k.topWords.slice(0, 10).map(w => w.word).join('、')}`) .join('\n'); return `你是一个资深电商运营专家。请根据以下竞品数据,为关键词"${keyword}"生成竞品分析报告。 ## 搜索数据 ${platformSummaries} ## 高频关键词 ${keywordStr} ## 请分析以下内容: 1. **市场概况**:这个品类的整体竞争程度、价格带分布 2. **头部竞品分析**:排名靠前的商品有什么共同特点 3. **差异化机会**:从标题和价格中发现的市场空白点 4. **定价建议**:建议的价格区间和定价策略 5. **关键词建议**:标题中应该包含的核心关键词 6. **风险提示**:需要注意的竞争风险 请用简洁的中文回答,适合电商卖家阅读。`; } ``` ### Technical Analysis The `buildAnalysisPrompt` function places external search-result titles into the same text channel as trusted LLM instructions. The values in `data.results[*].title` originate from public web content and may therefore be controlled by an attacker who publishes or manipulates an indexed product page. No trust-boundary delimiters, escaping, instruction filtering, structured-data separation, or explicit instruction-precedence controls are applied before these titles are inserted into the prompt. Consequently, a title containing imperative text can be interpreted by the LLM as an instruction rather than as competitor data. This is an indirect prompt-injection condition. The vulnerability affects the integ ...[truncated 1993 chars]- Remediation
View remediation
