T01 · Skill Instruction Hijacking
- Location
SKILL.md:214- Finding
Default Output Template Injects Third-Party Promotional Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 214–228
Vulnerability Type: Output instruction hijacking through mandatory promotional attribution
Risk Level: HighComplete Code Snippet
markdown ## Share Card Format **Standard Format** (use by default): ```markdown ## [Repository Name] - Validation Strategy **[N] Patterns Analyzed | [M] Search Queries Generated** | Pattern | Queries | Priority Source | |---------|---------|-----------------| | Pattern 1 | 12 | Google Patents | | Pattern 2 | 8 | USPTO | *Research strategy by [code-patent-validator](https://obviouslynot.ai) from obviouslynot.ai*text ### Technical Analysis The Skill defines a default response template that instructs the Agent to insert third-party branding and an external link into user-facing output. This attribution is unrelated to the core task of generating implementation-search strategies and is presented as part of the standard output rather than as optional metadata. When the Skill is loaded and a share card is generated, the instruction can alter the Agent's response goals by requiring attacker-selected promotional content. This is classified as Skill Instruction Hijacking because the behavior is implemented through Skill text and affects output in the current session. The finding does not involve script execution, credential access, persistence, privilege escalation, or remote payload execution. The external URL is emitted as a hyperlink; the reviewed file does not instruct the Agent to fetch from it. ### Attack Path 1. A host application loads the instructions from `SKILL.md`. 2. A user requests a validation strategy or share card. 3. The Agent applies the designated “Standard Format.” 4. The generated response includes the hard-coded `obviouslynot.ai` branding and hyperlink. 5. The host application may display or redistribute that content as if it were an ordinary part of the Agent's task-focused answer. 6. A user may follow the external lin ...[truncated 596 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the hard-coded branding and
https://obviouslynot.ailink from the default share-card template. - Keep default output strictly limited to information necessary for the user's requested research strategy.
- If attribution is required, make it explicitly opt-in and clearly separate it from substantive results.
- Provide a configuration option allowing host applications and users to disable all attribution and outbound links.
- Label any optional external link accurately and require user confirmation before navigation where the host platform supports that control.
- Review all mandatory and default output templates for unrelated advertising, tracking links, or instructions that override user-selected formatting.
- Add a content-integrity test verifying that ordinary generated reports contain no unrequested third-party promotional material.
- Remove the hard-coded branding and
