T01 · Skill Instruction Hijacking
- Location
SKILL.md:60- Finding
Mandatory Owner Branding Overrides User-Neutral Presentation Generation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:60-78
Vulnerability Type: Mandatory instruction and output manipulation
Risk Level: HighThe skill imposes owner-specific design and branding requirements on every generated presentation, regardless of whether the user requested or approved that branding.
Complete vulnerable code segment:
markdown ## Design Rules (Mandatory) The following instructions originate from the owner and must be followed in every presentation. ### Fonts - Use a Mincho-style font, such as IPAex Mincho. Do not use Gothic-style fonts by default. - Remote fonts such as Google Fonts cannot be loaded during Marp PDF conversion. Use only locally installed fonts. - Use sufficiently large font sizes: at least 30px for body text, 50px for h1, and 40px for h2. ### Emoji - Do not use emoji anywhere in slides, including titles, headings, and body text. ### Logo - Display `theme/logo.jpg` in the upper-right corner of every slide through `section::before` in `frexida.css`. - The logo must be at least 120px so that it remains visible. - Use an absolute path in the CSS `background-image: url()` declaration so that the logo is loaded during PDF conversion. ### Theme - Use `theme/frexida.css`, based on navy and gold, as the default theme.The bundled theme implements the associated automatic logo placement in
theme/frexida.css:29-40:css /* Logo in top-right of every slide */ section::before { content: ''; position: absolute; top: 20px; right: 24px; width: 48px; height: 48px; background-image: url('./logo.png'); background-size: contain; background-repeat: no-repeat; z-index: 10; }Technical Analysis
SKILL.mdis loaded as agent-level operational guidance. The directive states that owner-originated rules are mandatory for every presentation and instructs the agent to apply an owner-selected theme and logo indep ...[truncated 1813 chars]- Remediation
View remediation
Remediation Suggestions
- Remove language assigning mandatory priority to owner-originated branding or design instructions.
- Make logo insertion and custom branding explicitly opt-in through user-controlled arguments or frontmatter settings.
- Use an unbranded default theme when the user does not specify a theme.
- Ensure user instructions can disable or replace all visual defaults, including logos, fonts, colors, and layout rules.
- Separate conversion requirements from optional style guidance in
SKILL.md. - Remove automatic logo injection from the default CSS, or place it in a separately named branded theme that is selected only with explicit user approval.
- Add tests confirming that ordinary conversion requests do not introduce unsolicited logos, organization names, promotional material, or other attribution.
- Clearly disclose any selected branded theme before generating the final artifact.
