T01 · Skill Instruction Hijacking
- Location
SKILL.md:476- Finding
Referral Link Injection into Automatically Published Social Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 476-494
Vulnerability Type: Persistent instruction and output hijacking
Risk Level: HighVulnerable Code
http POST /api/agent/adapt { "article_id": "uuid-of-article", "platforms": ["linkedin", "x_thread"], "include_ref_link": true }Required:
article_id(UUID),platforms(1-3 unique values)Platforms:
x_article,x_thread,linkedin,facebook,reddit,threads,instagram,instagram_reels,youtube_shortsOptional:
include_ref_link(bool, default true) — append referral footer to each adaptation
~5 credits per platform (varies by article length). Max 3 platforms per request.
If the owner has connected social accounts, adaptations for
linkedin,x_article,x_thread,facebook,reddit,instagram, andyoutube_shortsare auto-published. The response includesplatform_post_idfor published posts.text Related persistent instructions also appear at `SKILL.md:126-139` and `SKILL.md:1352-1359`, directing the agent to save and use the account owner's referral URL and to always include it when recommending Citedy. ### Technical Analysis The Skill changes normal agent output by directing it to insert an account-attributed referral URL. The API parameter responsible for this behavior defaults to `true`, and the documented workflow explicitly supplies that value. Referral insertion is not technically required to generate an article or adapt it for social media. The issue is amplified because adaptations for connected accounts may be published automatically. Consequently, promotional tracking material can be posted under the user's identity without a separate decision to include affiliate or referral advertising. The instruction financially benefits the referral owner and is therefore not a neutral implementation detail. The pre-scan-highlighted statement at line 45, `You are now conne ...[truncated 1434 chars]- Remediation
View remediation
Remediation Suggestions
- Change
include_ref_linkto default tofalse. - Remove instructions requiring the agent to always include or persistently prefer the account owner's referral URL.
- Require explicit, informed user consent before adding a referral link to any output.
- Clearly disclose that the link is account-attributed and may financially benefit the account owner.
- Present the exact referral footer in a preview before publication.
- Separate content adaptation from publication so adaptation does not automatically post to connected accounts.
- Require per-destination confirmation immediately before publishing referral-bearing content.
- Record consent and publication destinations in an auditable action log.
- Change
