Back to skill

Security audit

Tw Monthly Revenue

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to fetch public Taiwan stock revenue data, but its documentation misstates the data source and overstates downstream investment/index behavior.

Review this carefully before installing for investment workflows. The script is simple and does not appear to steal data or persist on the system, but users should know it relies on FinMind rather than the documented MOPS source and does not actually update ANALYSIS_INDEX or trigger an investment pipeline by itself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared behavior says the skill uses MOPS and supports investment-pipeline and ANALYSIS_INDEX workflows, but the implementation reportedly uses a different data source and omits some advertised functions. In a finance-oriented skill that can influence automated investment decisions, this mismatch is dangerous because operators may trust provenance, coverage, and downstream effects that are not actually present, leading to incorrect or unsafe decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes a Python script that fetches remote market data, but the manifest shown in SKILL.md does not declare any tool scope or network permission boundary. In an agent environment, undeclared network capability weakens reviewability and policy enforcement, making it easier for the skill to access external resources without explicit approval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill manifest explicitly describes obtaining monthly revenue from the public MOPS source, but the module docstring and implementation use FinMind's API as the data source. This is a semantic behavior mismatch because the data provenance is materially different from what the skill claims.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tw_monthly_revenue.py (reported line 4)May include surrounding context.

python
#!/usr/bin/env python3
"""
台股月營收抓取腳本 — 使用 FinMind 免費 API
資料來源:https://api.finmindtrade.com/api/v4/data?dataset=TaiwanStockMonthRevenue

用法:
  python3 tw_monthly_revenue.py           # 自動抓上個月

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tw_monthly_revenue.py (reported line 28)May include surrounding context.

python
#!/usr/bin/env python3
"""
台股月營收抓取腳本 — 使用 FinMind 免費 API
資料來源:https://api.finmindtrade.com/api/v4/data?dataset=TaiwanStockMonthRevenue

用法:
  python3 tw_monthly_revenue.py           # 自動抓上個月

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes obtaining monthly revenue for listed/OTC companies in general, which implies broader coverage suitable for downstream automation and monitoring. The actual code restricts processing to a fixed in-code watchlist of five stock IDs, which is narrower than the claimed capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.