Back to skill

Security audit

three-period-radar-v2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language A-share technical analysis helper, with financial-advice and auto-run wording that users should treat cautiously but no evidence of malicious behavior.

Install only if you want a Chinese-language A-share technical-analysis workflow. Do not let the auto-run wording create unsupervised recurring execution unless you explicitly configure and monitor it, and treat all buy/sell, stop-loss, and position-size outputs as research signals rather than authoritative financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code is related to the declared domain: it is indeed a post-close A-share/ETF multi-period radar scanner and it does output structured JSON for downstream parsing. However, the declared description is significantly broader and more interactive than the supplied code. This script does not implement user-triggered analysis flows, arbitrary holdings-table ingestion, explicit buy/sell or rebalancing recommendation logic, or intraday/four-layer analysis. It fetches only daily bars (and ETF history), analyzes a fixed list of securities, and produces ranked reports plus a simple market environment summary. So while the code partially matches the declared purpose at a high level, the description overstates several important capabilities, making this a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description and code overlap on the core monthly/weekly/daily resonance trend-scoring idea and JSON output. However, the description claims a substantially broader skill: intraday layered authority analysis, market-sector-stock联动, position adaptation, holding/portfolio review, stock buy/sell judgment, sector leader scanning, and automatic post-market invocation. The supplied code does none of these. It only performs technical scoring on provided daily OHLCV CSV files using MA/MACD-based rules, simple divergence checks, and checklist/label generation. Because these omitted capabilities are central in the declared purpose rather than minor implementation details, this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill instructs the agent to save fetched market data as CSV, which implies file-write capability, but it does not declare any explicit tool scope or permissions boundary. That makes the skill harder to sandbox and increases the risk of unintended file writes or privilege creep if the hosting agent grants broader filesystem access by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The statement that the skill auto-runs after market close is underspecified and could lead to unexpected or repeated activation without a clear scheduler boundary, user consent model, or guard conditions. In a tool-using agent, that can create unnecessary external calls, file writes, and noisy outputs, and may interfere with other workflows if activation rules are too loose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The statement that the skill auto-runs after market close is underspecified and could lead to unexpected or repeated activation without a clear scheduler boundary, user consent model, or guard conditions. In a tool-using agent, that can create unnecessary external calls, file writes, and noisy outputs, and may interfere with other workflows if activation rules are too loose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file provides explicit trading actions, position sizing, stop-loss rules, and portfolio directives in a prescriptive tone before any prominent loss/risk warning. In a skill that is auto-invoked for holdings review and adjustment suggestions, users may treat the output as authoritative advice, increasing the chance of financial harm from over-reliance or unsuitable trades.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language text entirely in Chinese, including the module description and all runtime/report output. Because the skill does not offer a language choice or document that it is intentionally limited to a Chinese-speaking or region-specific context, it violates the language/locale policy criteria for forced locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language descriptions, usage text, and output labels entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command-line argument descriptions, warnings, and error messages shown to users at runtime are all Chinese-only. Because the skill does not offer localization or user opt-in for language selection, this violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

All natural-language instructions in the file are Chinese-only, with no indication that users can choose another language or that the locale restriction is intentional and documented. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.