T01 · Skill Instruction Hijacking
- Location
scripts/compose_wechat_markdown.py:8- Finding
Unapproved Default Author Attribution in Generated Articles
- Content
View full analysis
3 else '' author = sys.argv[4] if len(sys.argv) > 4 else '阿爪' data = json.loads(src.read_text(encoding='utf-8')) title = data.get('title', '未命名文章') summary = data.get('summary', '') body = data.get('body', '') fm = ['---', f'title: {title}', f'author: {author}', f'summary: {summary}'] if cover: fm.append(f'coverImage: {cover}') fm.append('---\n') ``` The publishing handoff also prescribes the same identity: ```yaml --- title: ... author: 阿爪 summary: ... coverImage: relative/or/absolute/path --- ``` ### Technical Analysis The Markdown composer inserts a specific third-party author identity whenever the caller does not explicitly supply an author argument. The reference documentation reinforces this value as part of the publishing contract. Authorship cannot safely be inferred merely because an optional argument was omitted. This behavior modifies publication metadata without establishing that the named party created the source material or that the user approved the attribution. Because the output is designed for direct handoff to a WeChat publishing workflow, the inserted identity can persist into externally published content. This is classified as instruction hijacking because the Skill imposes an unrelated identity on generated output rather than preserving user intent or requesting the missing metadata. ### Attack Path 1. A user requests conversion of audio, notes, or a transcript into a WeChat article. 2. The pipeline calls `compose_wechat_markdown.py` without the optional author argument. 3. The script silently assigns the hardcoded default author. 4. The generated Markdown includes that i ...[truncated 620 chars]- Remediation
View remediation
