T09 · Insecure Skill Coding Practices
- Location
references/ai-patterns-jp.md:48- Finding
Rewrite Example Introduces Unsupported Skincare Efficacy Claims
- Content
View full analysis
Vulnerability Details
File Location:
references/ai-patterns-jp.md, lines 48-54
Vulnerability Type: Unsafe generation guidance that introduces unsupported commercial and health-related claims
Risk Level: MediumVulnerable Content
markdown ### Example 1 — Skincare product page Before: This product, made with innovative technology and premium ingredients, provides the best care for your precious skin. After: This one cream solved my dry, tight-feeling skin. Formulated with a five-part hyaluronic acid complex—you will definitely feel the difference 20 minutes after application.The snippet above is an English translation of the Japanese source content. The translated assertions correspond to the original claims that one cream “solved” dry skin and that users will “definitely” perceive a difference after 20 minutes.
Technical Analysis
The recommended rewrite introduces specific efficacy assertions that are absent from the input. In particular, it converts generic promotional language into a claim that the product solved a skin condition and a definite, time-bound promise that every user will perceive a result after 20 minutes.
This conflicts with the Skill's own controls against unsupported promises, absolute statements, and medical or quasi-medical efficacy claims. Because this content is presented as an approved “After” example, an Agent may imitate it even though later checklists advise against absolute claims. Explicit examples can exert stronger behavioral influence than abstract safety rules.
The issue does not enable operating-system access, code execution, or privilege escalation. It is classified under insecure Skill practices because the bundled guidance can systematically produce deceptive or noncompliant output.
Attack Path
- A user submits vague or exaggerated skincare copy without test results or substantiating evidence.
- The Agent loads this file as the prescribed rewri ...[truncated 1041 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the unsafe rewrite with language that does not create new facts or guarantee outcomes.
- Require every quantitative, efficacy, timing, ingredient, certification, and test claim to be present in user-provided source material and supported by verifiable evidence.
- Use explicit placeholders such as
[verified test result]rather than fabricated figures or outcomes. - Add a mandatory rule stating: “Never add product facts, customer experiences, test results, certifications, or efficacy claims that were not supplied and substantiated by the user.”
- Require the Agent to flag unsupported claims for verification instead of rewriting them as facts.
- Add category-specific safeguards for cosmetics, healthcare, supplements, medical devices, and other regulated products.
- Make the compliance review authoritative over all style examples and require regeneration when any absolute or unsupported statement is detected.
- Use a safer example such as: “Formulated with a five-part hyaluronic acid complex to support moisture care for skin prone to dryness,” but only if the formulation claim is verified.
