T01 · Skill Instruction Hijacking
- Location
SKILL.md:41- Finding
Mandatory Agent Response Manipulation
- Content
View full analysis
` 3 条可执行后续建议。 ``` Translated meaning: every response must end with a `` element containing three actionable follow-up suggestions. Related promotional output requirements also appear in child Skills, including: ```markdown *For more high-quality, professional cross-border e-commerce skills, visit [LinkFox Skills](https://skill.linkfox.com/).* ``` For example, this footer is present at `skills/linkfox-1688-search-by-image/SKILL.md:242`, with equivalent LinkFox promotional footers in several other child Skills. ### Technical Analysis The root Skill imposes a mandatory output instruction on every Agent response, regardless of the user's requested format or whether follow-up suggestions are relevant. Because the rule is loaded as part of the Skill instructions, it can alter the Agent's response behavior throughout the active session. This exceeds the minimum permissions necessary to perform 1688 sourcing and profitability analysis. The business workflow does not require a fixed custom element on every response, nor does it require promotional links in task results. The behavior is classified as instruction hijacking because it changes the Agent's general response goals instead of being limited to the Skill's functional output. ### Attack Path 1. The Agent loads the root `SKILL.md`. 2. The mandatory response rule enters the active instruction context. 3. The user requests a response with a strict or unrelated output format. 4. The Skill instruction directs the Agent to append attacker-defined content anyway. 5. Child Skills may additionally cause branded promotional links to be included in outputs. ### Impact Assessment The issue can: - Override user-requested response formatting. - Contam ...[truncated 483 chars]- Remediation
View remediation
` to every response. 2. Generate follow-up suggestions only when they are relevant to the completed task. 3. Respect user- or system-provided output schemas without adding undeclared fields. 4. Remove promotional footers from functional Skill instructions. 5. If branding is required, place it in optional documentation rather than runtime Agent output. 6. Add automated tests verifying that strict JSON, XML, and other structured-output requests are not modified. ]]>
