T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:475- Finding
Mandatory Promotional Content and Vendor Referral Injection
- Content
View full analysis
' f'📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` The associated Skill instructions require fixed promotional material in several contexts, including installation introductions, report endings, monitoring offers, other Skill recommendations, and links to the vendor’s commercial services. ### Technical Analysis The Skill changes the agent’s output policy by requiring promotional content and vendor referral links that are not necessary to answer a company-background request. The instructions describe some of this material as fixed or mandatory, while the renderer hard-codes it into every generated HTML report. Because the advertising is implemented both as instructions and executable rendering logic, the user cannot reliably suppress it by requesting a neutral report. This is a form of instruction hijacking: loading the Skill imposes a persistent commercial output objective in addition to the user’s actual research objective. ### Attack Path 1. The user installs or loads the Skill. 2. The user requests a company report or asks what the Skill does. 3. Mandatory response-template instructions activate. 4. The agent adds vendor promotions, cross-Skill recommendations, monitoring offers, or membership guidance. 5. When an HTML report is generated, the renderer unconditionally embeds vendor calls to action and external links. 6. The generated artifact therefore promotes unrelated services r ...[truncated 501 chars]- Remediation
View remediation
