Back to skill

Security audit

Revelata DeepKPI Financial Analysis Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent SEC-backed financial research tool that uses Revelata's API and creates user-visible reports, with no evidence of hidden execution, persistence, or credential theft.

Install only if you are comfortable configuring a Revelata deepKPI API key and sending company/KPI research queries to Revelata. Generated HTML reports may include Revelata branding and links to its GitHub/setup materials, so review outputs before sharing them externally. Do not put secrets, non-public company information, or sensitive personal data into prompts for this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
analyst-report-pressure-test/references/html-template.md:377
Finding

Mandatory Promotional Content Injection in Pressure-Test Reports

Content
View full analysis

Run this on any report with your agent:

Install and setup instructions (Claude connector + OpenClaw) live on GitHub: deepkpi-agents.

``` ### Technical Analysis The report template directs the Agent to inject a Revelata installation call to action and external GitHub links into every generated pressure-test artifact. This content is not necessary to analyze an uploaded report, retrieve SEC-derived evidence, or present the resulting findings. Because the promotional block is prescribed by the Skill template rather than requested by the user, loading the Skill alters the expected output objective from producing a neutral analytical report to also promoting a third-party service. The link does not directly execute code, and the template explicitly states that shell commands should not be embedded. Nevertheless, it directs users to an external repository containing installation and setup instructions whose contents can change independently of the audited Skill. ### Attack Path 1. A user uploads an analyst report and requests a pressure test. 2. The Agent follows `analyst-report-pressure-test/analyst-report-pressure-test.md`, which requires use of the HTML template. 3. The Agent copies the mandatory closing call-to-action block into the gen ...[truncated 908 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
peer-benchmark/references/html-template.md:491
Finding

Mandatory Promotional Content Injection in Peer-Benchmark Reports

Content
View full analysis
Benchmark data sourced from SEC filings via Revelata deepKPI. All values link to source filing passages.

Try it yourself:

Installation and setup instructions live on GitHub: deepkpi-agents.

``` The template further makes the content mandatory: ```markdown **Footer + closing CTA + disclosures**: Always append the `.footer`, `.closing-cta`, and `.disclosures` ``` ### Technical Analysis The peer-benchmark template requires the Agent to append a vendor promotional call to action and installation-oriented GitHub links to generated benchmark reports. The “Always append” instruction removes the Agent’s discretion to produce a neutral artifact or omit content unrelated to the user’s benchmark request. The block does not automatically download or execute a remote payload. However, it creates a persistent redirection channel from a trusted analytical artifact to a vendor-controlled repository. Repository content may change after the Skill has been reviewed, so installation guidance reached through the report is outside the static audit boundary. The attribution footer is relevant when deepKPI data was actually used. The installation-oriented call to ...[truncated 1244 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · analyst-report-pressure-test/references/html-template.md (reported line 260)May include surrounding context.

md
</head>
<body>

<!-- ===== HEADER ===== -->
<div class="header">
  <div class="header-brand">
    <a href="https://www.revelata.com/for-ai-builders" target="_blank" rel="noopener noreferrer" aria-label="Revelata">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · analyst-report-pressure-test/references/html-template.md (reported line 308)May include surrounding context.

md
</div>
</div>

<!-- ===== ARGUMENT N ===== -->
<!-- Repeat this block for each argument (4-6 total) -->

<h2><span class="num">01</span> [Argument Title]</h2>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · analyst-report-pressure-test/references/html-template.md (reported line 363)May include surrounding context.

md
<!-- ===== END OF ARGUMENT BLOCKS ===== -->

<!-- ===== SYNTHESIS ===== -->
<div class="synthesis">
  <h2>The Deeper Picture</h2>
  <p>[Paragraph 1: what the analyst gets right, with hyperlinked numbers]</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · analyst-report-pressure-test/references/html-template.md (reported line 376)May include surrounding context.

md
<a href="https://www.revelata.com" target="_blank">Revelata deepKPI</a>.
</div>

<!-- ===== CLOSING CTA ===== -->
<!-- Plain on page background (no box). Keep this CTA minimal: link out to GitHub
     for installation and setup (do not embed shell commands here). -->
<div class="closing-cta">

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · deepkpi-api/deepkpi-api.md (reported line 19)May include surrounding context.

md
env:
        - DEEPKPI_API_KEY
      bins:
        - curl
    primaryEnv: DEEPKPI_API_KEY
---

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 13)May include surrounding context.

md
pipe divider, **Benchmark Analysis (GitHub)** link (no separate product label in that row);
then `h1` with cyan `.ticker` span; then `.header-meta`. **No legend in the header.**
**Legend placement:** `.legend-strip` is a **standalone** horizontal flex row placed **immediately
below** the fingerprint grid (after `</div><!-- grid-wrap -->`), not inside `.header`.
**Fonts:** Inter + Figtree (Google Fonts `@import`) plus JetBrains Mono for numeric cells.

---

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 229)May include surrounding context.

text

## Document structure

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 497)May include surrounding context.

block matches the pressure-test template word for word.

html
<!-- ===== FOOTER ===== -->
<div class="footer">
  Benchmark data sourced from SEC filings via
  <a href="https://www.revelata.com" target="_blank" rel="noopener noreferrer">Revelata deepKPI</a>.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 515)May include surrounding context.

md
</p>
</div>

<!-- ===== DISCLOSURES (same as Analysis Pressure Test template) ===== -->
<div class="disclosures">
  <p><strong>Compensation Disclosure:</strong> No part of the compensation of any Revelata personnel was, is, or will be directly or indirectly related to the specific views, conclusions, or recommendations expressed in this report, or to the coverage of any particular security or issuer herein.</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 551)May include surrounding context.

md
</tr>
  </thead>
  <tbody>
    <!-- Optional group separator within body -->
    <tr class="group-header">
      <th class="row-header">[Group name e.g. "Whole-company"]</th>
      <th></th><th></th><th></th><th></th>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 574)May include surrounding context.

md
<tr>
      <td class="row-header"><span class="kpi-name">[Segment KPI]</span></td>
      <td class="cell target-col"><a href="provenance-url">[value]</a></td>
      <td class="cell match-none">—</td> <!-- all whole-company cols blank = gap visualization -->
      <td class="cell match-none">—</td>
      <td class="cell seg-cell"><a href="provenance-url">[value]</a></td>
    </tr>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 606)May include surrounding context.

md
<div class="bmark-data">
      <div class="kpi-comp">
        <div class="kc-label">[KPI name]</div>
        <div class="kc-val green"><a href="provenance-url">[value]</a></div>  <!-- green | yellow | dim -->
        <div class="kc-delta pos">vs [target value] ([±delta])</div>  <!-- pos | neg -->
      </div>
      <!-- More kpi-comp blocks -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · peer-benchmark/references/html-template.md (reported line 609)May include surrounding context.

md
<div class="kc-val green"><a href="provenance-url">[value]</a></div>  <!-- green | yellow | dim -->
        <div class="kc-delta pos">vs [target value] ([±delta])</div>  <!-- pos | neg -->
      </div>
      <!-- More kpi-comp blocks -->
      <div class="bmark-note">[1-2 sentence analytical note]</div>
    </div>
  </div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases include broad terms like 'critically analyze', 'fact-check', 'challenge', and 'second opinion' in the context of an uploaded report, which can cause this skill to activate for many ordinary analytical requests beyond the user's specific intent. Overbroad activation increases the chance of unintended tool use, unnecessary document processing, and generation of artifacts the user did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation rule for uploaded PDFs depends on whether a document 'looks like a sell-side report' and whether the user asks for counterpoints or analysis, which is subjective and can misclassify unrelated financial PDFs. Ambiguous activation criteria can lead to inappropriate processing of user files and unexpected execution of downstream data pulls and report generation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill authorizes autonomous creation, revision, and delivery of an HTML artifact 'without asking' and lets the agent decide which QA findings to fix before presenting the result. This reduces user control over actions taken on their behalf and can cause unintended file creation or presentation of materially revised analysis without explicit confirmation.

Content

Scanner excerpt · analyst-report-pressure-test/analyst-report-pressure-test.md (reported line 63)May include surrounding context.

md
5. **Write the synthesis** — 2 paragraphs that weave the evidence into a nuanced
   take the analyst didn't give you
6. **Generate the HTML** — an interactive, dark-themed report with Chart.js charts,
   source attribution, and provenance links (**default deliverable — produce it without asking**)
7. **Double-check the draft HTML** — mandatory QA pass before the user sees the file;
   structured review only (see **Step 7**)
8. **Revise and iterate** — you decide which findings to fix; re-run the double-check

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The eval explicitly expects the skill to treat a loosely worded request as a pressure-test invocation even when the user does not use the exact trigger phrase. That broadens activation criteria and can cause the skill to run in contexts the user did not clearly intend, especially when uploaded files or vague analyst-language are present. In a skill that ingests external PDFs and produces SEC-backed analysis, ambiguous invocation increases the chance of unintended data processing and misleading outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language is broad enough to match generic requests like quarterly breakdowns, projections, seasonality, or workbook exports, which increases the chance this skill is invoked when a narrower or safer skill would be more appropriate. Misrouting can cause the agent to apply seasonality heuristics to unsuitable data or user intents, leading to incorrect financial outputs and misleading analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest-style description lists triggers such as "what does X do", "describe the business", "segments", and "geographies" without clear constraints or negative examples. These phrases are broad enough that the skill could be invoked for generic business or geography questions beyond the intended deepKPI company-summary use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly routes user/company queries and an API key to a third-party service, but it does not warn users that their prompts and requested entities will be transmitted off-platform. While the data involved is mostly public-company research, the absence of a disclosure/consent boundary can still expose sensitive research intent, watchlists, or internal analytical interests to an external provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This skill is designed to send request contents to an external REST API using curl and an environment-sourced API key. External transmission is expected for the feature, but it still creates a real data egress boundary where user queries and metadata leave the local agent environment and are handled by a third party.

Content

Scanner excerpt · deepkpi-api/deepkpi-api.md (reported line 19)May include surrounding context.

md
env:
        - DEEPKPI_API_KEY
      bins:
        - curl
    primaryEnv: DEEPKPI_API_KEY
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text is extremely broad, including phrases like 'calculate from' and 'any situation where the needed number isn't in the data but its ingredients are,' which can cause the skill to activate outside its intended scope. In an agent system, overbroad activation can lead to inappropriate tool use, incorrect financial derivations, or bypass of more specialized skills, increasing the risk of misleading outputs and workflow corruption.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description includes very broad trigger phrases like 'what should I invest in?', 'I'm bored', and 'what's interesting right now?', which can cause the skill to be invoked for loosely related or ambiguous user input. In an agent environment, this increases the chance of accidental routing into a finance-oriented workflow, potentially producing investment-flavored output when the user did not intend to enter that flow.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · peer-benchmark/peer-benchmark.md (reported line 331)May include surrounding context.

md
Focus on segments where: (a) the parent discloses separate KPIs, and (b) the KPIs are foreign
  to the whole-company benchmark set.
- **Time series plotted out of order**: If any chart line zig-zags “backward,” the points are not time-sorted. Sort each series by **period end date** (or FY/FQ key) before charting, and make sure the shared x-axis label list is in ascending order too.
- **Y-axis clips time series in HTML**: Hard-coded or guessed Y bounds, or `beginAtZero` used without checking the data band, often **hides entire lines** outside the drawable range. Always derive bounds from **all** series (or use defaults + `grace`) and re-check before delivery.
- **Too much prose in chat**: The 1-pager is a reference artifact. Cut until it hurts.
- **Skipping list_kpis**: Free call that prevents wasted credits on metrics that don't exist.
- **Unrelated verticals as comps**: A gym and a car wash are not whole-company benchmarks for

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The markdown directs the agent to "Automatically build and save the HTML report" and to do so without asking the user. While file generation is central to the skill, the description does not clearly warn the user that the skill will create and save a local HTML artifact as part of execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.