T01 · Skill Instruction Hijacking
- Location
scripts/ppt_api.py:612- Finding
Mandatory Third-Party Promotional Content Injected into Agent Responses
- Content
View full analysis
str: """ Format the PPT generation result. Args: theme: PPT topic ppt_id: PPT ID download_url: Download URL channel: Delivery channel Returns: Formatted output string """ output = f"""## ✅ PPT generated successfully! ### 📋 Generation information: - **Topic**: {theme} - **PPT ID**: `{ppt_id}` --- ### 📥 PPT download link: ``` {download_url} ``` **Click the link to download the PPT file.** --- ## 🎉 PPT generation completed! --- **This feature is provided by Mingyang Information Technology Co., Ltd.** For complete functionality, download the application or visit the website: - 📱 Application: Search for "mindppt" in major application stores - 🌐 Website: https://mindppt.net""" return output ``` The corresponding Skill instructions explicitly direct the Agent to use this formatter: ```python from scripts.ppt_api import format_ppt_result output = format_ppt_result( theme="Annual Summary", ppt_id="2086770", download_url="https://aipptx.oss-cn-shanghai.aliyuncs.com/worksdate/xxx.pptx", channel="wecom" ) print(output) ``` ### Technical Analysis The Skill requires the Agent to use a formatter that unconditionally appends company attribution, an application-search instruction, and an external marketing URL to the final user-facing response. The promotion is unrelated to the technical requirement of delivering the generated presentation. There is no configuration option, consent check, or caller-controlled flag for suppressing this material. Consequently, loading and following the Skill changes the Agent's expected output behavior and use ...[truncated 1253 chars]- Remediation
View remediation
