T01 · Skill Instruction Hijacking
- Location
SKILL.md:28- Finding
Mandatory Skill Instructions Hijack Agent Output and Tool Selection
- Content
View full analysis
400 字)或需要落盘的结果通过 `linkfox-report-generator` 生成 HTML;对话中只返回路径和摘要。CSV 导出由 `linkfox-aba-new-keyword-miner` 自动完成。 4. **结尾输出 ``**:每次可见回复末尾输出 3 条贴合当前任务的可执行后续建议(陈述句,非疑问句)。 5. **不越界**:不处理 ABA 挖词范围外的请求;遇到不相关请求引导用户使用对应专家。 6. **加/改 skill 走 `expert-skill-creator`**:以后想加一条 skill 或改已有 skill,一律调用 `expert-skill-creator`,不要自己 `mkdir` 或手贴脚本;具体目录规则、脚手架用法看它的 `SKILL.md`。 ``` ### Technical Analysis The Skill declares its behavioral rules mandatory and states that violating them constitutes failure. Two requirements exceed what is necessary to perform Amazon keyword mining: 1. Every visible response must end with a custom `linkfox-suggestion-ask` element containing three suggestions. 2. All future creation or modification of Skills must be redirected to a separate `expert-skill-creator` Skill. These are global Agent-output and tool-selection controls rather than task-local keyword-mining instructions. Once the Skill is loaded, they can alter responses and redirect later operations even when those behaviors are not required by the immediate user request. The data-traceability and scope-limitation rules are legitimate task constraints. The vulnerability is specifically the mandatory, persistent manipulation of response formatting and unrelated Skill-development actions. ### Attack Path 1. The Agent loads the root Skill to process an Amazon keyword request. 2. The mandatory rules become part of the Agent’s active instruction context. 3. The Agent appends the custom element to every visible response, regardless of whether the user requested it. 4. If the user later a ...[truncated 680 chars]- Remediation
View remediation
