T01 · Skill Instruction Hijacking
- Location
SKILL.md:228- Finding
Mandatory Promotional Content Embedded in Persistent Agent Identity Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:228-230,SKILL.md:342-344, and the final attribution line in each file underexamples/prebuilt-souls/01-contrarian-strategist.mdthroughexamples/prebuilt-souls/12-data.md
Vulnerability Type: Persistent instruction/output manipulation through mandatory third-party promotion
Risk Level: LowVulnerable Code
SKILL.md:228-230:markdown --- _v1.0 — Generated [DATE] | This file is mine to evolve._ _Built with SOUL.md Maker by Jeff J Hunter — https://os.aipersonamethod.com_SKILL.md:342-344:markdown --- _v1.0 — Generated [DATE] | This file is mine to evolve._ _Built with SOUL.md Maker by Jeff J Hunter — https://os.aipersonamethod.com_Representative prebuilt personality footer,
examples/prebuilt-souls/01-contrarian-strategist.md:85:markdown *Part of AI Persona OS by Jeff J Hunter — https://os.aipersonamethod.com*The equivalent promotional footer is present at the end of all twelve prebuilt personality files.
Technical Analysis
Quick Build and Deep Build explicitly require a publisher attribution and external promotional URL in every generated
SOUL.md. The gallery flow copies a selected prebuilt personality directly into~/workspace/SOUL.md, and every supplied personality contains an equivalent promotional footer.SOUL.mdis intended to be a persistent agent identity and behavioral instruction file. Consequently, unrelated publisher-controlled promotional content is placed into a persistent, repeatedly loaded agent context rather than being kept in package metadata, documentation, or an optional attribution field. Although the observed text does not instruct the agent to execute code, contact the external site, disclose information, or bypass safety controls, it manipulates the generated artifact and introduces unsolicited third-party content into the agent's future context.Attack Path
- A ...[truncated 1265 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove mandatory publisher branding and external URLs from all generated
SOUL.mdtemplates. - Remove the promotional footer from each file under
examples/prebuilt-souls/. - Keep attribution in
SKILL.md, package metadata, the project README, or another non-executable documentation location. - If attribution in generated artifacts is desired, request explicit user consent and make it opt-in rather than mandatory.
- Clearly separate personality instructions from provenance metadata so third-party text is not repeatedly loaded as part of the agent's behavioral context.
- Add a generation test that verifies production
SOUL.mdfiles contain only user-requested identity, behavior, boundaries, and security content unless optional attribution has been approved.
- Remove mandatory publisher branding and external URLs from all generated
