Back to skill

Security audit

Investment Analysis & Portfolio Management Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a methodology-only investment skill with no code execution, but it gives actionable trading and tax guidance without clear financial-risk disclaimers or human-approval guardrails.

Install only if you want a structured investment-analysis playbook. Treat its outputs as educational research support, not personalized financial, legal, or tax advice; verify data independently and require explicit human approval before making trades, changing allocations, or acting on tax-harvesting suggestions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill markets portfolio construction, risk management, and trade execution guidance without clear warnings that outputs may influence real financial decisions. In an agent setting, this increases the chance that users treat generated content as actionable investment advice, potentially leading to harmful trades or unintended execution behavior without adequate human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives highly actionable investment, trading, tax, and portfolio-management instructions, including position sizing, stop-losses, allocation models, and execution checklists, but does not warn users that this is generalized educational content rather than personalized financial, investment, or tax advice. That omission increases the risk that users will treat the output as professional advice and make consequential financial decisions without appropriate suitability, jurisdiction, or fiduciary review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation makes a strong claim that the skill is pure methodology with no external dependencies or scripts. However, the README also presents the skill as an installable package and links to external resources, which makes the 'zero dependencies' claim misleading as written, even if the core functionality may still be methodology-only.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README presents example invocations like "Analyze BTC" and "Portfolio health check" as triggers, but it does not define whether these are exact phrases, examples only, or what constraints limit activation. In a markdown skill description, this lack of trigger specificity can cause unintended invocation during ordinary finance-related conversation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.