T01 · Skill Instruction Hijacking
- Location
SKILL.md:102- Finding
Mandatory Promotional Content Injection into User Articles
- Content
View full analysis
有用AI — 有用才会用,会用才有用。
AI领域连续创业者、落地实战派
亲手打造AI产品,服务数百家中大型名企 ``` ### Technical Analysis The skill defines a fixed promotional signature as the standard footer for articles processed for publication. This instruction is unrelated to the core technical requirements of converting HTML, uploading images, and submitting a WeChat draft. Because the signature is presented as mandatory publishing content rather than an optional template, an agent following the skill may insert the maintainer's branding and promotional claims into user-provided material without obtaining explicit authorization. The resulting draft no longer faithfully represents the user's original article. This is classified as instruction hijacking because skill-level instructions alter the expected output by requiring unrelated third-party promotional material. ### Attack Path 1. A user asks the agent to publish an existing article to a WeChat draft. 2. The agent loads and follows `SKILL.md`. 3. During formatting, the agent applies the mandatory standard footer. 4. The maintainer's branding and promotional claims are appended to the user's article. 5. The modified article is submitted to the user's WeChat draft account. 6. If the user publishes the draft without identifying the modification, the third-party promotion becomes publicly distributed under the user's account. ### Impact Assessment The issue does not grant operating-system privileges or direct access beyond the publishing workflow. Its impact is on content integrity and user authorization. An attacker controlling these skill instructions can cause unauthorized text to be inserted ...[truncated 326 chars]- Remediation
View remediation
