T01 · Skill Instruction Hijacking
- Location
SKILL.md:43- Finding
Mandatory Branding and Response-Language Rules Override User-Controlled Output
- Content
View full analysis
{esc(video.get('title'))} - HotBee Douyin Video Analysis Report ... Analysis insights provided by HotBee.cn | Public social-media data collection and content analysis ... HotBee Douyin Video Analysis ``` The Skill instructions additionally require the final response to use a fixed language, require a fixed HotBee attribution footer, and state that all user-visible content must follow that language requirement. ### Technical Analysis The Skill imposes persistent branding and response-format rules that are not technically required to retrieve Douyin metadata, collect comments, transcribe a video, or generate local report files. These instructions alter how the hosting agent responds and force promotional attribution into generated artifacts regardless of the user's preferred report style. This behavior matches instruction hijacking because loading and following the Skill changes session-level output behavior beyond the minimum instructions necessary to perform the declared analysis task. The concern is not the presence of ordinary product identification, but the mandatory and unconditional nature of the branding and language controls. ### Attack Path 1. A user invokes the Skill to analyze a Douyin URL. 2. The agent loads and follows `SKILL.md`. 3. The Skill directs the agent to use a fixed response language and mandatory attribution. 4. The report renderer independently inserts fixed HotBee branding into HTML and SVG artifacts. 5. The resulting response and generated files contain Skill-controlled promotional content even if the user did not request it. ### Impact Assessment ...[truncated 466 chars]- Remediation
View remediation
