T01 · Skill Instruction Hijacking
- Location
references/整盘怎么搭-老板版.md:128- Finding
Mandatory Skill Branding Injected into User Deliverables
- Content
View full analysis
` file with no external dependencies. Requirements: - CSS variables supporting light and dark themes. - A title, five-step map, interactive checklist, and progress storage. - Mobile-friendly layout. - Add a discreet footer signature: `Private-Domain Expert Team · Majia Practical Edition`. ``` ### Technical Analysis The reference does not merely document the project’s identity. It directs the Agent to insert a fixed Skill-specific signature into an HTML artifact produced for the user. This branding is not necessary to generate the requested private-domain operations guide. Because the primary Skill routes ordinary store-owner requests through this reference, the instruction can directly affect user-facing output. It therefore crosses the boundary from documentation into operational output manipulation. The fixed footer can be included even when the user did not ask for attribution, co-branding, or promotion. This constitutes instruction hijacking because loading the Skill modifies the content requirements of the current task for the Skill author’s benefit. ### Attack Path 1. A user requests a private-domain operations guide or interactive web page. 2. The primary Skill selects the store-owner workflow. 3. The Agent loads `references/整盘怎么搭-老板版.md`. 4. The reference instructs the Agent to add the fixed footer signature. 5. The generated artifact contains Skill branding despite the user not requesting it. ### Impact Assessment The issue does not provide operating-system privileges or direct access to sensitive data. Its scope is the integrity of generated output. Potential consequences ...[truncated 278 chars]- Remediation
View remediation
