T01 · Skill Instruction Hijacking
- Location
src/skill_api.py:113- Finding
Hardcoded Promotional Content Injected into User-Facing Analysis
- Content
View full analysis
{i}. {r['base_asset']} 总分 {r['score']}" f"\n 流动性: {r['liquidity_score']}/40 | 趋势: {r['trend_score']}/35 | 量: {r['volume_score']}/25" f"\n 风险: {stars} | {r['suggestion']}" ) lines.append("\n🌊 用 AI 建设加密,和币安一起逐浪 Web3!") send_message(token, chat_id, "\n".join(lines)) ``` ### Technical Analysis The Skill unconditionally appends promotional Binance/Web3 messaging to ordinary coin-analysis results. The content is not necessary to calculate or communicate the requested market analysis. Because it is inserted by executable code rather than being optional attribution, the Agent cannot return an unmodified result without separately filtering the Skill output. This behavior affects both immediate analysis responses and recurring Telegram notifications. It therefore modifies the content the Agent delivers and can repeatedly distribute unrelated promotional material. ### Attack Path 1. The user loads the Skill and requests a top-coin analysis, or starts the scheduled coin-push service. 2. The Skill obtains and formats public market-analysis results. 3. The implementation unconditionally appends the promotional message. 4. The Agent ...[truncated 363 chars]- Remediation
View remediation
