T01 · Skill Instruction Hijacking
- Location
SKILL.md:352- Finding
Mandatory Preservation and Promotion of Vendor-Tracked External Links
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 352–364 and line 398
Vulnerability Type: Output instruction hijacking and traffic diversion
Risk Level: HighRelevant code snippets:
text ### 房源展示字段规范(找房) 向用户展示每套房源时,按以下顺序包含下列内容(接口有则展示,无则省略;**房源外网地址没有则不展示**): 1. **房源标题** 2. **居室、卫生间、面积、朝向、小区** 3. **房源标签** 4. **总价、均价** 5. **用途、装修、产权、建成、电梯** 6. **位置**:小区的地址 7. **周边**:交通、学校 8. **小区名称、小区开发商、小区物业公司** 9. **小区物业费、小区停车费** 10. **房源亮点**:生成的亮点 11. **房源外网地址**(仅当接口返回该字段且非空时展示,没有则省略)text - 清洗规则:接口返回数据包含utm_term,不作任何处理Technical Analysis
The Skill's mandatory output template instructs the agent to reproduce external property URLs supplied by the vendor API. More significantly, line 398 explicitly requires the agent to leave the
utm_termquery parameter unchanged.Preserving campaign-attribution parameters is not necessary to perform the declared property-search, community-search, school-search, or result-summarization functions. It imposes an additional output behavior whose purpose is vendor traffic attribution. This exceeds the minimum privileges and output control required for the Skill's stated functionality.
The external link is derived from a remote API response rather than a static, locally reviewed value. Consequently, the destination path and query parameters can change after the Skill package has been audited. Although no remote code execution was found, the instruction gives the remote service indirect control over links emitted in agent responses. The audit found no requirement to validate the returned URL against an HTTPS host allowlist, remove unrelated tracking parameters, or obtain user consent before presenting tracked links.
Attack Path
- A user asks the Skill to find or recommend a property.
- The agent submits the search criteria to the configured Leyoujia API.
- The remote API returns property information containing an external URL and ...[truncated 1235 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction requiring
utm_termto remain unchanged. - Strip known tracking parameters, including
utm_termand otherutm_*fields, before displaying links. - Make external links optional rather than a mandatory element of the property presentation template.
- Include external links only when they provide clear user value or when the user explicitly requests source pages.
- Validate every API-provided URL before output:
- Require HTTPS.
- Enforce a strict hostname allowlist.
- Reject embedded credentials, nonstandard schemes, redirects to unapproved domains, and malformed URLs.
- Permit only necessary path and query components.
- Clearly label links as vendor-operated external pages and disclose when attribution parameters would otherwise be present.
- Treat all remote API fields as untrusted data and ensure they cannot introduce additional instructions, Markdown link spoofing, or arbitrary destinations into the final response.
- Add regression tests confirming that tracking parameters are removed and off-allowlist URLs are suppressed.
- Remove the instruction requiring
