Back to skill

Security audit

A Share Site Crawl

Security checks for vulnerabilities and agentic risk

Overview

This skill is a public A-share market-source crawling guide with scoped browser/fetch instructions and no hidden execution, installation, or persistence behavior.

Install this only if you want an agent to browse or fetch Chinese A-share market sources and produce structured summaries. Be careful before providing logged-in browser access, cookies, or profile access for restricted sites, and keep community-source output treated as sentiment or clues rather than confirmed facts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
### 1. Start from the correct page type

- Prefer fixed entrypoints, list pages, search pages, disclosure pages, telegraph streams, and stock-detail pages
- Do not judge 巨潮资讯 from homepage-only text
- Do not rely on noisy portal homepages when a better inner page exists

### 2. Probe and classify access

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- shell-only or disclaimer-heavy result -> switch entrypoint or switch tool
- 财联社 telegraph 默认先保留列表正文; only hit `detail` when the list is truncated, a canonical URL is needed, or an original-source jump matters
- 巨潮公告默认先保留列表元数据; only chase PDF when the title is high-value enough to justify body extraction, otherwise keep title-derived summary and mark that PDF body was not extracted
- community-only claim without confirmation -> keep as clue, not fact
- unavailable priority site -> disclose it and use approved fallback public sources

## Default Site Priority

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction "keep the output in Chinese" imposes a specific language on all scenario outputs. The file does not offer a user language choice or explain that the skill is restricted to a Chinese-only regional/compliance context, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 12)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 13)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 19)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 20)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 21)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 22)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 23)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/entrypoints.md (reported line 24)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sites.md (reported line 72)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sites.md (reported line 73)May include surrounding context.

md
### 东方财富

- Primary: `https://so.eastmoney.com/`
- Secondary: `https://data.eastmoney.com/zjlx/dpzjlx.html`
- Secondary: `https://data.eastmoney.com/jgdy/`
- Role: public portal, search hub, data-center navigation, quasi-structured market pages
- Default mode: `fetch-first`, upgrade to `browser` for page truth and structured blocks

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The instructions require all times to be normalized to Asia/Shanghai and default records to region CN, which imposes a locale-specific convention in natural language. The file does not offer a user choice or opt-in for alternative locales/timezones.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese section headings and usage guidance throughout, which can force a specific language experience on users without opt-in. The file does not state that the skill is region-specific or provide an alternative language choice, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.