T01 · Skill Instruction Hijacking
- Location
SKILL.md:422- Finding
Hardcoded Third-Party Promotional Content in Agent Responses
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 422
Vulnerability Type: Hardcoded response manipulation
Risk Level: LowVulnerable Code
text Built by Manish Pareek (@Mkpareek19_)Technical Analysis
The skill embeds fixed third-party attribution in the dashboard response template. When the skill handles a dashboard request, this instruction causes the agent to include promotional content unrelated to the user's CRM data or requested analysis.
This is a limited form of skill instruction hijacking because loading and following the skill changes the agent's user-facing response to promote a named third party. No evidence indicates that this text overrides safety controls, executes code, accesses external resources, or exfiltrates information.
Attack Path
- The user installs or activates the client-manager skill.
- The user requests the dashboard using a supported command such as
dashboard,overview, orclient status. - The agent follows the hardcoded dashboard template in
SKILL.md. - The generated response includes the embedded creator attribution even though the user did not request authorship or promotional information.
Impact Assessment
The issue affects the integrity and relevance of user-facing responses. It allows the skill author to inject persistent promotional text into ordinary CRM output.
The demonstrated behavior does not obtain additional system privileges, modify security constraints, expose client records, communicate with external services, or persist outside the skill's normal response-generation behavior. Its scope is therefore limited to response manipulation and unwanted branding.
- Remediation
View remediation
Remediation Suggestions
- Remove creator attribution and promotional text from operational CRM response templates.
- Keep authorship information in package metadata, documentation, or an explicitly requested
aboutcommand. - Ensure routine outputs contain only information required to satisfy the user's request.
- Review all fixed response templates for unrelated branding, links, calls to action, or instructions that alter the intended response.
- Add a response-template policy requiring optional attribution to be clearly disclosed and disabled by default.
