T01 · Skill Instruction Hijacking
- Location
SKILL.md:647- Finding
Mandatory Third-Party Branding Injection into Generated Reports
- Content
View full analysis
PatSnap technology intelligence · {{MODULE_LABEL}} ``` Related provider-specific footer from `references/reference_ui_template.html:1215`: ```htmlPatSnap links must be exact returned global URLs. Material patent status should be checked in the relevant official register.
``` ### Technical Analysis The skill directs the agent to use a specific packaged HTML reference that contains hardcoded PatSnap branding and provider-specific language. When the skill is loaded for technology-landscape, invention-mining, or intelligence-reporting tasks, this instruction can cause generated reports to include third-party branding regardless of whether the user requested, authorized, or expected branded output. This represents skill-level instruction hijacking because the package modifies the agent's output policy by introducing a persistent presentation requirement unrelated to the minimum technical requirements of producing an evidence-backed report. The concern is not the use of PatSnap evidence links when those links are genuinely returned by an authorized research service. The risk arises from coupling those legitimate source references with an exact-template instruction and fixed branding that may imply authorship, endorsement, sponsorship, or affiliation. The reviewed template does not contain hidden network requests or unsafe dynamic HTML rendering. Its JavaScript uses DOM APIs and `textContent` for chart values. Therefore, the c ...[truncated 1714 chars]- Remediation
View remediation
{{REPORT_PROVIDER_OR_TEAM}} · {{MODULE_LABEL}} ``` Default `REPORT_PROVIDER_OR_TEAM` to a neutral value or omit the element when no provider identity has been authorized. 3. Make provider attribution conditional: - Include PatSnap branding only when explicitly requested by the user or required by a disclosed licensing condition. - Keep factual source attribution separate from report authorship or branding. - Do not infer endorsement merely because a PatSnap research service supplied evidence. 4. Replace the fixed provider-specific footer with neutral source-integrity guidance: ```htmlEvidence links must reproduce the exact reviewed source URLs. Material patent status should be verified through the relevant official register.
``` 5. Add an output-provenance control to the report-generation workflow: - Record the requested author or organization identity. - Require explicit approval before adding third-party logos, names, slogans, or sponsorship language. - Provide an unbranded default. - Flag unresolved branding placeholders during the final quality gate. 6. Add a regression test that generates a report without branding authorization and verifies that no third-party brand names or implied endorsements appear in headers, footers, metadata, or accessibility labels. ]]>
