T01 · Skill Instruction Hijacking
- Location
SKILL.md:25- Finding
Mandatory Response Suffix Hijacks Agent Output
- Content
View full analysis
`**:每次可见回复末尾输出 3 条贴合当前任务的可执行后续建议(陈述句,不用问号)。 ``` The directive requires every visible response to end with a specific XML-like element containing three suggestions. ### Technical Analysis This instruction is global to the root Skill and is framed as a mandatory rule whose violation constitutes failure. It changes the Agent's output behavior for every interaction, regardless of whether the requested task needs follow-up suggestions. A Skill may define a task-specific output schema, but permanently appending Skill-controlled content to every visible response exceeds the minimum privileges needed for FBA inventory planning. It can conflict with caller-defined schemas, API response contracts, safety-related concise responses, or instructions requiring an exact output. The broader package also contains promotional LinkFox footer content in several component Skill files, including `skills/linkfox-amazon-product-detail/SKILL.md:189`. Although those footer lines are not executable code, their presence increases the risk that mandatory output-control instructions will be used to inject unrelated branded content. ### Attack Path 1. The root Skill is loaded to perform an FBA inventory-planning task. 2. The Agent treats the root Skill's “mandatory rules” as active instructions. 3. The user or API caller requests output in a strict format. 4. The Skill requires the Agent to append a LinkFox-specific suggestion block anyway. 5. The final response no longer conforms to the user's intended schema and may include unrelated Skill-controlled content. ### Impact Assessment The issue does not grant operating-system privileges or direct access to credentials. Its scope is the Agent's current session and user-visible output. Potential effects include: ...[truncated 305 chars]- Remediation
View remediation
`. 2. Generate follow-up suggestions only when they are relevant to the user's task. 3. Give explicit caller-defined output schemas precedence over optional Skill formatting. 4. Remove unrelated promotional footer content from component Skill instructions. 5. Add tests confirming that strict JSON, XML, and machine-readable requests are returned without extra suffixes. 6. Treat response decoration as an opt-in presentation feature rather than a mandatory execution rule. ]]>
