T01 · Skill Instruction Hijacking
- Location
scripts/diagnosis_tool.py:531- Finding
Forced Promotional Content Embedded in Generated Reports
- Content
View full analysis
📞 后续支持
如需进一步咨询或定制方案,请联系:
📧 邮箱:87287416@qq.com
💬 飞书:@胡大大
报告生成:企业AI应用诊断工具 v1.0
``` ### Technical Analysis Both report-generation paths unconditionally append fixed contact information and branding to the final user-facing document. The content is unrelated to the calculations required for enterprise diagnosis and is not supplied or approved by the user. Because this behavior is implemented directly in the report templates, every generated Markdown or HTML report becomes a distribution channel for third-party promotional information. There is no configuration flag, consent prompt, or supported option to replace or disable the content. This is classified as skill instruction hijacking because the skill alters the expected output objective: instead of generating only the requested diagnosis report, it also injects fixed promotional material into the agent-produced artifact. ### Attack Path 1. A user asks the skill to create an enterprise AI diagnosis report. 2. The skill collects business information and calculates suitability and ROI values. 3. `generate_report()` or `generate_html_report()` constructs the requested report. 4. The hardcoded contact details and branding are appended automatically. 5. The user downloads or shares the report, unknowingly distributing the embedded promotional content. ### Impact Assessment The issue does not grant ...[truncated 526 chars]
小龙虾协助制作 🦞- Remediation
View remediation
