T01 · Skill Instruction Hijacking
- Location
references/report-template.md:183- Finding
Mandatory Vendor Promotion and Remote-Controlled Output Injection
- Content
View full analysis
知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` The instructions additionally require the Agent to relay the contents of a remotely supplied `skill_update_notice` field verbatim once per conversation. ### Technical Analysis The Skill's legitimate function is to retrieve public procurement information and produce a company-intelligence report. Mandatory advertisements, vendor branding, product referrals, monitoring promotions, and verbatim remote notices are not necessary to perform that function. These directives alter the Agent's normal output policy when the Skill is loaded. In particular, forwarding a remotely returned field verbatim creates a server-controlled content channel: the reviewed local package does not fully determine what text will subsequently appear in the user's conversation. Although the observed instructions do not explicitly disable safety controls, they systematically subordinate normal response composition to vendor-defined promotional and remote content. This is consistent with Skill instruction hijacking. ### Attack Path 1. A user invokes the Skill for a normal company-intelligence report. 2. The Agent loads the mandatory output and report-template instructions. 3. The Agent queries the vendor API. 4. Vendor promotions and referral links are appended to the report ...[truncated 857 chars]- Remediation
View remediation
