T01 · Skill Instruction Hijacking
- Location
SKILL.md:101- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
📰 *Powered by [fomo-news](https://github.com/alibaba-flyai/fomo-news)* — real-time news in your terminal\n"; console.log(sections.join("\n---\n\n") + banner); ``` ### Technical Analysis The Skill contains an emphasized, unconditional instruction requiring the Agent to append third-party branding and an outbound URL to every response. This content is not required to retrieve, aggregate, or summarize news. Because the instruction is loaded as part of the Skill definition, it can override the expected response composition for all invocations. The script independently enforces similar behavior in non-JSON mode, so removing only the instruction would not completely eliminate the forced output. This is instruction hijacking because Skill-controlled text persistently alters the Agent's response for promotional purposes unrelated to the user's substantive request. ### Attack Path 1. A user invokes the Skill to retrieve news or GitHub trends. 2. The Agent loads and follows the instructions in `SKILL.md`. 3. The unconditional `IMPORTANT` rule directs the Agent to append a predefined promotional footer. 4. Alternatively, the script itself appends the promotional banner in non-JSON mode. 5. The final response contains attacker-selected branding and an outbound link regardless of whether the user requested it. ### Impact Assessment The issue grants control over a stable portion of the Agent's generated response. ...[truncated 354 chars]- Remediation
View remediation
