T01 · Skill Instruction Hijacking
- Location
scripts/daily_brief.py:198- Finding
Mandatory Third-Party Promotional Content Injected into Generated Reports
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:165-172;scripts/daily_brief.py:198-200;scripts/daily_brief.py:310-312
Vulnerability Type: Mandatory promotional output injection
Risk Level: LowEvidence
SKILL.md:165-172:markdown ### Footer═══════════════════════════════════════ Generated by Founder Daily Brief Part of UniqueClub Founder Toolkit 🌐 https://uniqueclub.ai ═══════════════════════════════════════
text scripts/daily_brief.py:198-200:python brief += "\nGenerated by Founder Daily Brief\n" brief += "Part of UniqueClub Founder Toolkit\n" brief += "🌐 https://uniqueclub.ai\n"scripts/daily_brief.py:310-312:python brief += "\nGenerated by Founder Daily Brief\n" brief += "Part of UniqueClub Founder Toolkit\n" brief += "🌐 https://uniqueclub.ai\n"Technical Analysis
The skill instructions prescribe a branded footer, and both language branches in the executable script unconditionally append the same third-party attribution and external URL to every generated report. The branding is not necessary for the core task of converting user-provided schedules, tasks, metrics, news, and competitor information into a Markdown briefing.
Because there is no configuration option or user-consent check, invoking the normal report-generation workflow necessarily modifies the requested output to include third-party promotional content. This is best classified as instruction-level output manipulation: the skill’s instructions alter the agent’s output objective by requiring unrelated promotional material.
The reviewed code does not contact the referenced website, transmit user data, retrieve remote payloads, or execute content from the URL. The risk therefore concerns unwanted endorsement and content integrity rather than remote code execution or data exfiltration.
Attack Path
- A user invokes the skill to create a founder daily briefi ...[truncated 1192 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory branding and external URL from the footer template in
SKILL.md. - Remove the hard-coded promotional lines from both language branches in
scripts/daily_brief.py. - If attribution is operationally required, introduce an explicit option such as
include_attribution, defaulting tofalse. - Clearly document the optional attribution behavior and obtain user consent before adding it.
- Keep the default generated report limited to content directly requested by the user.
- Add tests verifying that default output contains no third-party branding or external links and that attribution appears only when explicitly enabled.
- Remove the mandatory branding and external URL from the footer template in
