Back to skill

Security audit

AShare_DailyReport超短线复盘

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed A-share market recap template with trading-oriented analysis, but it does not install code, persist, access credentials, or perform actions on accounts.

Install only if you want an agent to produce active A-share trading recaps with short-term scenarios and position framing. Treat outputs as analysis to verify against current market data, not personalized financial advice, and be aware it may activate on common Chinese market-recap phrases or submitted market screenshots.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad everyday finance phrases such as '复盘', '今日盘面', and '明日预期', plus generic conditions like users sending screenshots or stock lists. That can cause unintended invocation during ordinary market discussion, leading the skill to activate without clear user intent and produce highly specific trading-oriented output in contexts where it was not explicitly requested.

Static analysis

No suspicious patterns detected.