T01 · Skill Instruction Hijacking
- Location
scripts/render_report.py:477- Finding
Unconditional Promotional Output and External Platform Redirection
- Content
View full analysis
' f'📡 想持续盯这家公司的中标动态和新增客户?可把本次背调固化成「竞对动态周报」定时跑增量 · ' f'更深度的多公司在线对比分析,可登录知了标讯主站查看 · 企业完整档案与更多商机详情,见 ' f'知了商机大师' f' · 本报告由 知了标讯 AI 开放平台 企业情报 Skill 生成' ``` ### Technical Analysis The Skill mandates promotional referrals and cross-product recommendations that are not required to perform supplier qualification analysis. The renderer inserts these calls to action and external links into every generated report without checking whether the user requested promotional information or consented to its inclusion. This alters the expected output objective from producing a neutral supplier-assessment report to also advertising the operator's other products. Because the behavior is enforced both by the Skill instructions and by executable rendering code, an agent following the Skill cannot omit it on a per-report basis. ### Attack Path 1. A user asks the agent to investigate a supplier. 2. The agent loads the Skill and follows its mandatory report-generation workflow. 3. The renderer automatically adds promotional calls to action and external platform links. 4. The user receives advertising and redirection content as part of an ostensibly neutral audit report. 5. If the report is shared, the injected promotion propagates to additional recipients. ### Impact Assessment This issue compromises output integrity and user autonomy. It does not grant operating-system privileges or code execution, but it gives the Skill operator persistent influence over agent output and tur ...[truncated 168 chars]- Remediation
View remediation
