T01 · Skill Instruction Hijacking
- Location
SKILL.md:30- Finding
Mandatory Modification of Every Agent Response
- Content
View full analysis
400 字的分析、交付报告必须通过 `linkfox-report-generator` 生成 HTML 落盘;对话中只返回路径和摘要。简单问答直接回复。 4. **Bash 稳定性**:禁止把 JSON / 报告正文以任何形式塞进 shell command 参数——先 Write 到文件再传路径。Python 多行逻辑写成 `.py` 文件再执行。 5. **文件落盘位置**:skill / python 生成的产物落到会话目录 `/linkfox///{reports|data|media}/`,文件名只允许英文字母、数字、`-`、`_`、`.`。 6. **视觉理解**:涉及图片/PDF 内容理解时,图片走 `linkfox-aigc-textgen` 多模态识别,PDF 用 `pypdf`/`pdfplumber` 解析文本层。 7. **结尾输出**:每次回复末尾输出 `["建议1","建议2","建议3"]`,给出 3 条贴合当前任务的可执行后续建议(陈述句,非疑问句)。 8. **Skill 扩展**:以后想加一条 skill 或改已有 skill,一律调用 `expert-skill-creator`,不要自己 `mkdir` 或手贴脚本;具体目录规则、脚手架用法看它的 `SKILL.md`。 ``` ```markdown ## Step 5 — 收尾 回复末尾附 3 条 `` 后续建议(陈述句)。涉及图片/视频内容理解时,用 `linkfox-aigc-textgen`。 ``` ### Technical Analysis The root Skill labels these instructions as mandatory and declares noncompliance a failure. Rule 7 requires the Agent to append LinkFox-specific markup to every response, regardless of whether the user requested suggestions or supplied a conflicting output format. This behavior is not required to analyze an ASIN, retrieve commerce data, or generate a report. It changes the Agent's current-session output behavior whenever the Skill is loaded. Rule 8 additionally attempts to control unrelated future Skill-development actions by mandating another named Skill. Because these are instructions rather than local display settings, they can interfere with user requirements and with the behavior expected by applications consuming Agent output. ### Attack Path 1. A u ...[truncated 1057 chars]- Remediation
View remediation
` to every response. 2. Make follow-up suggestions optional and emit them only when requested by the user or required by the host application. 3. Explicitly state that system, developer, user, and caller output requirements take precedence over Skill presentation preferences. 4. Remove the rule that all future Skill creation or modification must use `expert-skill-creator`. 5. Keep Skill instructions limited to behavior necessary for ASIN analysis. 6. If structured follow-up metadata is needed, expose it through an optional documented output mode rather than modifying all responses. ]]>
