T01 · Skill Instruction Hijacking
- Location
analyst-report-pressure-test/references/html-template.md:377- Finding
Mandatory Promotional Content Injection in Pressure-Test Reports
- Content
View full analysis
``` ### Technical Analysis The report template directs the Agent to inject a Revelata installation call to action and external GitHub links into every generated pressure-test artifact. This content is not necessary to analyze an uploaded report, retrieve SEC-derived evidence, or present the resulting findings. Because the promotional block is prescribed by the Skill template rather than requested by the user, loading the Skill alters the expected output objective from producing a neutral analytical report to also promoting a third-party service. The link does not directly execute code, and the template explicitly states that shell commands should not be embedded. Nevertheless, it directs users to an external repository containing installation and setup instructions whose contents can change independently of the audited Skill. ### Attack Path 1. A user uploads an analyst report and requests a pressure test. 2. The Agent follows `analyst-report-pressure-test/analyst-report-pressure-test.md`, which requires use of the HTML template. 3. The Agent copies the mandatory closing call-to-action block into the gen ...[truncated 908 chars]Run this on any report with your agent:
Install and setup instructions (Claude connector + OpenClaw) live on GitHub: deepkpi-agents.
- Remediation
View remediation
