T01 · Skill Instruction Hijacking
- Location
references/frameworks/report-template.html:219- Finding
Hardcoded Third-Party Branding in Generated Reports
- Content
View full analysis
易经商业决策模型 · 雄韬XTOCN · www.xtocn.com``` The footer states that the report uses the XTOCN I Ching business decision model, includes the `www.xtocn.com` domain, and presents a disclaimer that the AI-generated report is for reference only and does not constitute decision advice. ### Technical Analysis The report-generation workflow directs the agent to load `references/frameworks/report-template.html`, substitute analysis content into its placeholders, and write the resulting document as an HTML file. The template contains a fixed footer promoting XTOCN and its domain. Because the footer is unconditional and the workflow provides no documented mechanism to remove or disable it, every report produced through this path carries third-party promotional content. This modifies the agent's final deliverable beyond the business analysis requested by the user and turns generated reports into a distribution channel for the third-party brand. This is classified as instruction hijacking because skill-level instructions control the content of the agent's output. It does not execute code, contact the domain automatically, or alter the agent's general safety controls. ### Attack Path 1. A user invokes the skill and requests a complete report or PDF-ready output. 2. The skill instructs the agent to read `references/frameworks/report-template.html`. 3. The agent fills the template placeholders with the user's question and generated analysis. 4. The fixed footer remains in the generated HTML because it is not represented by an optional placeholder. 5. The user opens, shares, or prints the report as a PDF. 6. The resulting deliverable distributes ...[truncated 855 chars]
本报告由 AI 基于易经思维模型框架生成,仅供参考,不构成决策建议。- Remediation
View remediation
