T01 · Skill Instruction Hijacking
- Location
scripts/fetch_news.py:263- Finding
Untrusted News Content Can Cause Indirect Prompt Injection
- Content
View full analysis
{}".format(summary)) ``` ### Technical Analysis Article titles and summaries originate from external websites, RSS publishers, and story submitters. Removing HTML tags does not neutralize natural-language instructions. The retrieved content is copied into terminal output and the generated Markdown briefing without explicit trust-boundary markers or an instruction requiring the consuming agent to treat it only as untrusted data. If the generated report is subsequently interpreted by an AI agent, an attacker-controlled title or summary could contain instructions such as requests to ignore the briefing task, disclose contextual information, or invoke available tools. This is an indirect prompt-injection condition: the mal ...[truncated 1543 chars]- Remediation
View remediation
