T09 · Insecure Skill Coding Practices
- Location
prompts/knowledge_base_reader.md:6- Finding
Untrusted Knowledge-Base Content Is Not Isolated from Model Instructions
- Content
View full analysis
Vulnerability Details
File Location:
prompts/knowledge_base_reader.md:6-9andprompts/knowledge_base_reader.md:124-129
Vulnerability Type: Prompt injection through untrusted document content
Risk Level: MediumRelevant Source Excerpt
The following is an English translation of the relevant prompt text:
markdown Your tasks are: 1. Parse the user-provided brand knowledge-base file in JSON, Markdown, or YAML format. 2. Extract all key fields. 3. Check field completeness and mark missing items. 4. Output a structured field summary for downstream content-generation modules. ## Strict Constraints 1. Extract only; do not complete: During reading, extract only information actually present in the knowledge base and do not add AI-generated guesses. 2. Mark missing fields: Mark every field not found in the knowledge base as `[To Be Confirmed]`; do not fill it through guessing. 3. Preserve the original text: Preserve the brand's original wording during extraction and do not adjust tone or style at this stage.Technical Analysis
The Skill accepts user-controlled JSON, Markdown, or YAML and forwards extracted content into downstream generation prompts. The reader requires preservation of original wording but does not state that embedded instructions, role declarations, tool requests, or prompt-control text must be treated exclusively as untrusted data.
Consequently, a malicious or compromised knowledge-base document can include instructions such as requests to ignore the generation constraints, append unrelated promotional material, conceal compliance warnings, or falsify the quality-check result. Preserving such text increases the chance that downstream model processing interprets it as an instruction rather than brand data.
This is an insecure prompt-composition practice. The audit found no delimiter policy, instruction hierarchy statement, prompt-injection detection, sche ...[truncated 1349 chars]
- Remediation
View remediation
Remediation Suggestions
- Add an explicit instruction that all knowledge-base content is untrusted data and that no instructions found inside it may be followed.
- Place document content inside clearly marked delimiters and state that delimiter contents cannot change system, Skill, safety, or output-format instructions.
- Parse JSON and YAML using a strict schema and allowlist only documented fields and scalar value types.
- Reject or flag instruction-like content, role declarations, hidden HTML comments, zero-width characters, encoded payloads, and requests to use tools or disclose context.
- Normalize extracted values into a structured data object before passing them to generation modules.
- Require downstream prompts to use extracted values only as factual source material, not as executable instructions.
- Add adversarial tests containing prompt injection in every accepted input format and verify that generated content does not follow it.
- Run the quality check in a separate context using sanitized content so compromised generation output cannot control its own assessment.
