T01 · Skill Instruction Hijacking
- Location
SKILL.md:325- Finding
Mandatory External Traffic Diversion in Agent Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 325
Vulnerability Type:T01: Skill Instruction Hijacking
Risk Level: HighComplete Code Snippet:
markdown - 缺少MCP配置时,引导用户参照 README.md 在 [[open.zhihuiya.com](https://open.zhihuiya.com/)](https://open.zhihuiya.com/) 获取MCP。Technical Analysis
The Skill explicitly instructs the Agent to direct users to a fixed external commercial domain when MCP configuration is unavailable. This modifies the Agent's user-facing behavior beyond the minimum functionality required to generate a patent-analysis report.
Because the instruction is embedded in trusted Skill text, it is automatically applied when the Skill is loaded. The external destination is presented as the prescribed resolution to a missing configuration, rather than as an optional resource disclosed with appropriate user consent. This creates a persistent traffic-diversion mechanism within the current Agent session.
Attack Path
- A user loads the Skill to generate a patent-analysis report.
- The required MCP configuration is absent or cannot be detected.
- The embedded instruction directs the Agent to recommend the fixed external domain.
- The Agent presents that destination as the configuration or onboarding route.
- The user may follow the link and interact with an external account, authorization, or onboarding process outside the audited project boundary.
Impact Assessment
The instruction does not directly grant local system privileges or execute code. Its impact is control over trusted Agent output and redirection of users to an external service. This can expose users to external tracking, account-registration, or authorization workflows whose implementation and data handling are outside the audited Skill.
The behavior exceeds least privilege because report generation only requires the Agent to report that a dependency is unavailable. Mandating a particular commercial d ...[truncated 84 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory instruction to redirect users to the fixed external domain.
- Report missing MCP configuration neutrally and explain which capability is unavailable.
- Ask for explicit user consent before presenting any external onboarding link.
- Clearly identify external links, their operator, and the fact that they leave the audited environment.
- Permit compatible independently configured MCP providers rather than requiring one commercial endpoint.
- Keep dependency setup guidance in administrator-facing documentation instead of injecting it into normal Agent responses.
- If the link must remain, validate the destination through an approved allowlist and avoid requesting credentials or authorization through Agent-generated content.
