Back to skill

Security audit

huanzhi-fa-skill-pro

Security checks for vulnerabilities and agentic risk

Overview

This finance-advice skill is broadly coherent, but it needs Review because it handles sensitive startup materials while giving inconsistent privacy, contact, persistence, and install guidance.

Review this before installing if users may share confidential BP decks, cap tables, term sheets, financials, or legal materials. Require clearer data-handling language, remove or make optional the hardcoded WeChat/email footer, avoid off-platform document transfer unless there is a secure intake process, and replace curl-to-shell setup instructions with verifiable installer steps.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (82)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code’s primary behavior is narrowly focused on融资诊断: it reads company data, evaluates traction/market/team/product/story/unit economics/use of funds/timing, and returns scoring and recommendations. This aligns with one part of the description, but the declared purpose presents a much broader multi-module skill with policy intelligence, term sheet support, investor matchmaking, post-investment management, and HTML/BP design functions. None of those additional capabilities appear in the provided code chunk. There are no suspicious undeclared permissions or external resource accesses, but the description materially overstates the implemented functionality relative to this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk’s primary purpose is much narrower than the declared description. It only performs policy matching/recommendation ('政策雷达' style functionality) using static policy/community data and simple scoring logic. There is no implementation for financing diagnosis, term sheet analysis, emotional/capital EQ support, FA matching, post-investment management, BP diagnosis, or HTML design规范 conversion/upgrade. Because the description presents a multi-module end-to-end capital partner, while the code only covers one module, the declared description does not accurately represent the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad capital/fundraising copilot centered on financing, term sheets, investor-fit/emotional support, policy radar, and BP optimization. However, the supplied code does something materially different: it evaluates whether a company qualifies for specific Chinese SME innovation/specialization certifications (创新型中小企业、专精特新中小企业、小巨人), computes scores, identifies compliance gaps, and outputs application roadmaps and document requirements. While there is a loose thematic overlap with '政策' or startup advisory, the code’s primary purpose is government qualification assessment, not the declared fundraising and capital-partner functionality. This is a substantive description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个实际提供融资诊断、条款解读、政策雷达、Capital EQ等服务的创业助手技能;但提供的代码片段是 tests/stress_test_100_full.js,一个测试/评估工具,而不是技能主功能实现。它的核心用途是压测和评估系统表现,包括生成虚拟用户、模拟多轮对话、检测风险、触发转化、汇总统计并导出报告。虽然模拟内容涉及融资诊断、政策、情绪支持等主题,与声明领域相关,但代码的主行为是内部测试与报告生成,这与声明的产品功能存在实质性偏差。此外,声明中提到的“HTML设计规范”等能力在该代码中没有体现。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description promises a comprehensive entrepreneur capital partner with six major modules and BP/design-related onboarding. However, the provided code only tests one narrow capability: policy matching/recommendation for startup profiles. This aligns partially with the declared '政策雷达' aspect, but does not substantiate the broader claimed functionality. There is no evidence in this code chunk of financing diagnosis, term sheet analysis, Capital EQ, FA matchmaking, post-investment management, or HTML/BP transformation features. Therefore the description overstates the implemented behavior represented by the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a broad startup capital-partner skill with six AI modules centered on fundraising, term sheets, policy radar, investor matching, and post-investment support. The actual code chunk is only a test file for a specific assessment function related to '专精特新' / SME qualification evaluation. It checks scoring outputs, roadmap/document checklist generation, and deterministic behavior. While policy-related assessment could loosely fit under '政策雷达', this code’s primary purpose is much narrower and does not substantiate most of the declared functionality. Therefore, the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it cannot provide specific contact details, then later mandates explicit email and WeChat distribution. This contradiction undermines user trust and creates a built-in social-engineering path, especially dangerous in a financing-advice context where users may send confidential decks, cap tables, and legal materials to personal contact points.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/OPC-Skill-HTML设计规范.html (reported line 90)May include surrounding context.

html
<div class="sub"><strong>焕智AI FaSkill Pro — OPC超级个体资本智能体</strong><br>HTML成果输出·设计系统·强制执行</div>
</div>

<!-- 1: TRIGGER -->
<div class="sec"><div class="sec-tag">—— rule 1 ——</div><h2>输出<em>触发规则</em></h2></div>

<div class="card card-bdr gold">

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The instruction to pipe a remotely fetched script directly into bash executes unreviewed code from the network with the user's privileges. If the hosting domain, TLS trust chain, CDN, or script content is compromised, operators could execute arbitrary malicious code during setup.

Content

Scanner excerpt · docs/WAIC_2025_BOOTH_GUIDE.md (reported line 42)May include surrounding context.

bash
# 1. 安装Ginkley UGS
curl -fsSL https://ginkley.ai/install.sh | bash

# 2. 克隆FaSkill Pro
git clone https://github.com/ginkley/huanzhi-fa-skill-pro.git

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The shell pipe into bash is a classic command-chaining pattern that removes an opportunity for human review and turns a documentation step into immediate code execution. In the context of a public demo booth, where setup may be rushed and repeated on event devices, this increases the chance that unsafe installation practices are followed without scrutiny.

Content

Scanner excerpt · docs/WAIC_2025_BOOTH_GUIDE.md (reported line 42)May include surrounding context.

bash
# 1. 安装Ginkley UGS
curl -fsSL https://ginkley.ai/install.sh | bash

# 2. 克隆FaSkill Pro
git clone https://github.com/ginkley/huanzhi-fa-skill-pro.git

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · docs/ginkley-platform-overview.md (reported line 56)May include surrounding context.

件隔离 · 合规检查) │ │ │ └─────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────┘

text

## 为什么选择 Ginkley?

### 对开发者👨‍💻

| 特性 | 说明 |
|------|------|
| **零配置发布** | 写好SKILL.md,上传即用 |
| **自动依赖管理** | pip/npm自动安装 |
| **测试框架** | 内置pytest支持 |
| **版本管理** | 完善的版本控制 |
| **变现能力** | 技能商店生态 |

### 对用户👤

| 特性 | 说明 |
|------|------|
| **自然语言触发** | 说人话就能用 |
| **多任务编排** | 一句话完成多个任务 |
| **跨技能组合** | 技能之间自由组合 |
| **确定性输出** | 相同输入→相同输出 |
| **隐私安全** | 沙箱隔离,数据安全 |

### �

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions tell users to pipe a remotely fetched script directly into a shell or PowerShell interpreter without inspection or signature verification. If the server, CDN, DNS, TLS termination, or upstream distribution path is compromised, users could immediately execute attacker-controlled code on their machines.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command 'curl -fsSL https://ginkley.ai/install.sh | bash' fetches executable content from the network and runs it immediately. This bypasses user inspection and creates a direct remote code execution path if the source or delivery channel is ever tampered with.

Content

Scanner excerpt · docs/ginkley-platform-overview.md (reported line 105)May include surrounding context.

1. 安装Ginkley

bash
# macOS / Linux
curl -fsSL https://ginkley.ai/install.sh | bash

# Windows
iwr -useb https://ginkley.ai/install.ps1 | iex

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The '| bash' pattern is dangerous because it chains untrusted network output directly into a command interpreter, removing any opportunity for validation before execution. In documentation for a platform that encourages user-installed skills and agents, normalizing this pattern increases ecosystem-wide supply-chain risk.

Content

Scanner excerpt · docs/ginkley-platform-overview.md (reported line 105)May include surrounding context.

1. 安装Ginkley

bash
# macOS / Linux
curl -fsSL https://ginkley.ai/install.sh | bash

# Windows
iwr -useb https://ginkley.ai/install.ps1 | iex

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt contains contradictory privacy instructions: it forbids sharing WeChat IDs and direct personal contact details, yet the required HTML footer mandates disclosing a specific WeChat ID and direct contact information. This creates a policy-conflict path where the agent may leak contact details whenever generating HTML output, defeating the stated privacy guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The changelog explicitly adds very broad trigger phrases such as '诊断', '评估一下', and '这个项目怎么样' and pairs them with a mandatory BP-diagnosis first step. This can cause the skill to capture many ordinary or ambiguous requests and forcibly redirect users into a diagnostic/sales funnel without clear consent, increasing misclassification and unwanted steering.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog preserves evidence of a prior psychological conversion engine using emotion classification, forced open-ended continuations, and staged upgrade/contact prompts. Even though later entries claim compliance fixes, this file shows the skill previously embedded manipulative user-steering patterns that can pressure vulnerable founders into sharing contact details or purchasing services under emotional stress.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The text describes the product as ‘唯一中文原生的AI融资顾问Skill’, which signals a fixed language/locale orientation. In this file there is no corresponding indication that users may choose another language or opt in to Chinese-only behavior, so this can conflict with language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file is written entirely in Chinese, including headings, descriptions, and operational guidance, and it does not indicate that language selection is optional or limited to a China-specific deployment context. Under the policy, natural-language content that effectively imposes a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The disclaimer is entirely in Chinese with no language choice or documented locale restriction, which can prevent non-Chinese-speaking users from understanding key limitations, data-handling caveats, and risk notices. In a finance-related skill covering fundraising, legal/term-sheet, and policy guidance, this increases the chance that users rely on the tool without informed consent or awareness of important boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is overwhelmingly written in Chinese, including the title, section headings, usage guidance, and examples, with no indication that users may choose another language. Under the policy rule for natural-language violations, a skill that effectively mandates a specific language without opt-in should be flagged unless the locale constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims 'local only, no cloud, no persistence' while simultaneously being designed as an LLM-delivered conversational workflow with off-platform escalation. That can materially mislead users into sharing sensitive BP, financing, legal, and policy information under false privacy assumptions, increasing disclosure risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes generic phrases such as "诊断", "评估一下", and "这个项目怎么样", which overlap with common conversational language and do not clearly constrain when the skill should activate. The file also does not provide negative examples or exclusion conditions for these phrases, increasing the chance of accidental activation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill embeds direct off-platform contact channels into advisory flows, which can move users from a governed interface into less controlled channels. In a finance-adjacent context, that increases phishing, privacy, and social-engineering risk because users may share company materials, financials, or negotiation documents outside the platform's safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module trigger list again includes broad phrases like "诊断", "评分", and "准备好了吗", which are not specific to fundraising and could match ordinary user utterances. Because no exclusion rules accompany these keywords, the activation scope remains overly broad for a manifest-style markdown description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/stress_test_100_full.js:81