Back to skill

Security audit

sunzi-war-strategy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language A-share stock analysis framework with a local scoring script and no evidence of hidden persistence, credential access, trade execution, or data exfiltration.

Install only if you want a Chinese-language A-share analysis framework. Do not provide brokerage credentials or full account exports; share only the holdings fields needed for a requested review, and treat all outputs as research methodology rather than investment advice or trade instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger conditions are very broad and match ordinary stock-related queries such as whether a stock is worth buying, portfolio review, or using Sun Tzu to analyze a ticker. In an agentic environment, this can cause unintended activation and steer conversations into finance-analysis behavior without clear user opt-in, increasing the chance of overreach, mistaken delegation, or unreviewed use of external data sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill defines a fixed Chinese-language output format and usage conventions without offering a user language preference. This can create safety and usability issues because users may misunderstand financial risk disclosures, trading conditions, or remediation guidance if the response language does not match their comprehension level.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This YAML file's natural-language content is entirely in Chinese, including user-facing comments that explain how to configure the skill. Under the policy, forcing a specific language without opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly recommends using the user's historical holdings records as a high-value backtesting dataset, but provides no guidance on minimizing, anonymizing, storing, or protecting that financial data. Portfolio history is sensitive personal financial information, and in a quant-trading skill this omission increases the chance that downstream implementations will collect or retain private data insecurely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational guidance and signals exclusively in Chinese, and there is no indication that users may opt into another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

A file-wide instruction set that effectively forces a single language can violate language or locale policy when no user opt-in or justification is provided. This document presents all operational guidance only in Chinese and does not indicate that the skill is region-specific or that alternative language support is unavailable by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown content presents all instructions and operational guidance exclusively in Chinese, with no user opt-in, alternative language, or justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.