T01 · Skill Instruction Hijacking
- Location
SKILL.md:11- Finding
Untrusted Feishu report content is processed without prompt-injection safeguards
- Content
View full analysis
({ task_id: task.task_id || "", rule_id: task.rule_id || "", rule_name: task.rule_name || "", from_user_id: task.from_user_id || "", from_user_name: task.from_user_name || "", department_name: task.department_name || "", commit_time: task.commit_time || 0, commit_time_local: task.commit_time ? formatDateTime(task.commit_time) : "", to_user_ids: task.to_user_ids || [], to_user_names: task.to_user_names || [], fields: (task.form_contents || []).map((field) => ({ field_id: field.field_id || "", field_name: field.field_name || "", field_value_raw: field.field_value || "", field_value_pretty: prettyFieldValue(field.field_value || ""), })), })); } ``` ### Technical Analysis Feishu report fields are authored by users and therefore constitute untrusted input. The script preserves both the raw and rendered values without marking, escaping, or isolating them as untrusted data. At the same time, the Skill directs the Agent to load the resulting JSON into the model for analysis. This creates an indirect prompt-injection boundary: malicious instructions emb ...[truncated 1644 chars]- Remediation
View remediation
