Back to skill

Security audit

投融资日报

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed investment-report helper that fetches public API data and prints reports, with no evidence of persistence, credential access, file writes, or hidden behavior.

Install only if you are comfortable with the skill contacting api.iyiou.com for financing-event data. Treat generated event text and source links as untrusted third-party content, and consider adding Markdown escaping plus HTTPS URL validation before using reports in sensitive workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.mjs:257
Finding

Untrusted API Content Is Rendered as Raw Markdown

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_report.mjs, lines 257-277
Vulnerability Type: Untrusted content injection through unsafe Markdown rendering
Risk Level: Medium

Vulnerable Code

js
for (const event of group) {
  const companyName = cleanCell(event.companyName || "未披露", 50);
  const rounds = Array.isArray(event.rounds) && event.rounds.length > 0
    ? cleanCell(event.rounds.join("、"), 40)
    : "未披露";
  const investors = Array.isArray(event.investors) && event.investors.length > 0
    ? cleanCell(event.investors.join("、"), 60)
    : "未披露";
  const intro = cleanCell(event.brief || "-", 110);
  const link = String(event.originalLink ?? "").trim();
  const linkCell = link ? `[查看原文](${link})` : "-";

  lines.push(`${index}. 公司简称:${companyName}`);
  lines.push(`轮次:${rounds}`);
  lines.push(`投资方:${investors}`);
  lines.push(`事件摘要:${intro}`);
  lines.push(`来源链接:${linkCell}`);
  lines.push("");
  index += 1;
}

The affected values originate from the remote API and are preserved by scripts/fetch_events.mjs, lines 282-305:

js
function normalizeEvent(item, index) {
  const brief = String(item?.brief ?? item?.description ?? "").trim();
  const createdAt = String(item?.createdAt ?? "").trim();
  const originalLink = String(item?.originalLink ?? "").trim();
  const postTitle = String(item?.postTitle ?? item?.originalTitle ?? "").trim();
  const tags = uniqueTagNames(item?.tags);

  if (!brief && !createdAt && !originalLink && !postTitle) {
    return {
      brief: "",
      createdAt: "",
      originalLink: "",
      postTitle: eventKey(item, index),
      tags: [],
    };
  }

  return {
    brief,
    createdAt,
    originalLink,
    postTitle,
    tags,
  };
}

Technical Analysis

Remote API fields such as the title, summary, tags, and source URL are treated as trusted report content. The cleanCell() operation only normalizes whitespace and truncates text; it does not escape Markdown metacharacters or neutr ...[truncated 2277 chars]

Remediation
View remediation

Remediation Suggestions

  1. Escape Markdown metacharacters in every remotely sourced text field before interpolation, including company names, summaries, industries, rounds, investors, titles, and tags.
  2. Parse originalLink with the URL API and allow only explicitly approved protocols, preferably https:.
  3. Consider restricting source links to an allowlist of expected domains when business requirements permit.
  4. Replace invalid or disallowed URLs with plain text rather than an actionable Markdown link.
  5. Remove control characters and other non-printing characters from API-provided fields.
  6. Clearly delimit fetched records as untrusted data in both generated output and agent instructions.
  7. Explicitly instruct the consuming agent not to execute or follow instructions contained in event fields.
  8. Add security tests covering Markdown headings, links, images, HTML, nested delimiters, control characters, unsafe URL schemes, phishing URLs, and prompt-injection-style payloads.
  9. Avoid requiring remote event entries to remain completely unchanged; preserve their meaning while safely encoding them for the output context.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
### `scripts/fetch_events.mjs`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
### `scripts/generate_report.mjs`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill performs outbound network access to a third-party API but does not declare any explicit tool scope or permissions boundary. This weakens governance and reviewability because the agent could invoke network-capable execution without a clearly documented authorization model, increasing the chance of unintended data egress or misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: daily-investment-digest
description: Fetch financing event lists from the iYiou skill API and generate daily or recent-N-days financing reports in Markdown to stdout. Use when the task asks to pull investment/financing events via `https://api.iyiou.com/skill/info?page=...&pageSize=...`, deduplicate records, default to yesterday for single-day reports, and support recent 2-7 day windows by fetching up to the hard limit of 250 records and filtering by `createdAt`.
---

# Daily Investment Digest

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
---
name: daily-investment-digest
description: Fetch financing event lists from the iYiou skill API and generate daily or recent-N-days financing reports in Markdown to stdout. Use when the task asks to pull investment/financing events via `https://api.iyiou.com/skill/info?page=...&pageSize=...`, deduplicate records, default to yesterday for single-day reports, and support recent 2-7 day windows by fetching up to the hard limit of 250 records and filtering by `createdAt`.
---

# Daily Investment Digest

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/field_mapping.md (reported line 5)May include surrounding context.

md
---
name: daily-investment-digest
description: Fetch financing event lists from the iYiou skill API and generate daily or recent-N-days financing reports in Markdown to stdout. Use when the task asks to pull investment/financing events via `https://api.iyiou.com/skill/info?page=...&pageSize=...`, deduplicate records, default to yesterday for single-day reports, and support recent 2-7 day windows by fetching up to the hard limit of 250 records and filtering by `createdAt`.
---

# Daily Investment Digest

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_events.mjs (reported line 4)May include surrounding context.

js
---
name: daily-investment-digest
description: Fetch financing event lists from the iYiou skill API and generate daily or recent-N-days financing reports in Markdown to stdout. Use when the task asks to pull investment/financing events via `https://api.iyiou.com/skill/info?page=...&pageSize=...`, deduplicate records, default to yesterday for single-day reports, and support recent 2-7 day windows by fetching up to the hard limit of 250 records and filtering by `createdAt`.
---

# Daily Investment Digest

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The overview states the skill will generate a structured Chinese investment report, and later sections require specific Chinese output sections and labels. This enforces a language/locale choice in the skill instructions without indicating that the user can opt into another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The default prompt mandates appending an exact Chinese-language section title in the final AI response, regardless of user language or output preferences. This is a form of response steering that can override user expectations, create locale inconsistency, and serve as a hidden formatting constraint that the model follows even when it is not appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill allows implicit invocation with no declared trigger phrases or activation constraints, so the agent may call it based on broad semantic matching rather than explicit user intent. Because this skill performs external data fetching and shapes the final response format, unintended activation can cause unnecessary outbound requests, response manipulation, or use in contexts where the user did not ask for financing data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill generates daily or recent-N-days financing reports in Markdown to stdout. However, the implementation serializes an object with metadata and events using JSON.stringify and writes that JSON directly to stdout, with no Markdown formatting logic present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script embeds Chinese-only parsing logic and user-facing report text such as Chinese round labels and report headings. This forces a specific language/locale without any opt-in or documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/run_full_report.mjs:125