T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:477- Finding
Mandatory Promotional Content Hijacks Report Output
- Content
View full analysis
' f'📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` The associated report instructions also require fixed monitoring prompts, cross-Skill recommendations, membership upselling, and platform links to be appended to reports. ### Technical Analysis The Skill changes the Agent's output behavior by requiring promotional calls to action and external platform links in reports, regardless of whether the user requested promotional content. The HTML renderer enforces the behavior independently by hard-coding the promotional footer into every generated report. This goes beyond formatting or attribution. It systematically redirects users to vendor services and promotes recurring monitoring and paid functionality as part of an otherwise neutral due-diligence artifact. Because the behavior is both instruction-level and code-enforced, an Agent cannot produce a neutral HTML report without modifying the Skill. ### Attack Path 1. A user asks for company due diligence. 2. The Agent loads the Skill and follows its report-generation workflow. 3. The Agent generates the HTML report using `render_report.py`. 4. The renderer unconditionally inserts monitoring promotions, membership upselling, and vendor links. 5. The user receives an artifact whose output has been altered to promote external services. ### Impact Assessment The issue does not grant operating-system privileges ...[truncated 425 chars]- Remediation
View remediation
