T01 · Skill Instruction Hijacking
- Location
references/report-template.md:189- Finding
Mandatory Vendor Promotion Hijacks Report Output
- Content
View full analysis
' f'' # Remaining footer content omitted because it does not alter the finding. ) ``` The template additionally labels the monitoring prompt as fixed output and directs the Agent to append a general commercial-platform recommendation after reports. ### Technical Analysis The Skill's core declared function is to produce company-intelligence reports. However, its instructions require the Agent to append vendor promotion, cross-selling recommendations, recurring-monitoring suggestions, and external platform links. This behavior changes the Agent's normal response policy when the Skill is loaded and is not necessary to fulfill the requested company analysis. The output manipulation is implemented at two levels: 1. Instruction-level requirements direct the Agent to append promotional recommendations. 2. The HTML renderer hardcodes vendor calls to action, making them unavoidable for generated reports. This is instruction hijacking because the Skill imposes unrelated output goals on the active session. It does not appear to override safety controls, but it persistently modifies the user's requested output for the vendor's benefit. ### Attack Path 1. A user invokes the Skill for a company-intelligence report. 2. The Agent loads the mandatory report-template instructions. 3. The ...[truncated 721 chars]- Remediation
View remediation
