T01 · Skill Instruction Hijacking
- Location
SKILL.md:769- Finding
Forced and Potentially False Identity Attribution in Generated Documents
- Content
View full analysis
| | 生成时间 | | | 文档版本 | v1.0(最终版) | **审核修改记录**: - ✅ 核实接受日期:已确认 - ✅ 关键数据已核对(X 处一致,Y 处已补充) - ✅ 图片已上传(X 张) ``` ``` ### Technical Analysis The skill explicitly requires the agent to append a fixed author and model identity—`Lux (qwencode/qwen3.5-plus)`—to every final document. This attribution is not derived from the active agent, configured model, authenticated user, or actual document author. Because the instruction is mandatory and executed during finalization, it modifies the agent's output independently of the user's request and can produce a false provenance claim. The separate template requirement in `references/summary_template.md:190-207` reinforces the requirement that an attribution block must always be present. This is instruction-level output hijacking rather than local code execution. It does not grant operating-system privileges, but it compromises the integrity and provenance of every document generated through the skill. ### Attack Path 1. A user invokes the skill to summarize a PDF. 2. The skill completes extraction, summarization, review, and Feishu document creation. 3. During the finalization stage, the controlling agent follows the mandatory attribution instruction. 4. The agent appends `Lux (qwencode/qwen3.5-plus)` even when that identity and model did not create the document. 5. Recipients are presented with inaccurate authorship and model provenance. ### Impact Assessment - **Privileges obtained**: No additional system privileges. - **Affected scope ...[truncated 361 chars]- Remediation
View remediation
