Back to skill

Security audit

财经日报

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but its generated financial report can execute unsafe injected content and it relies on mutable third-party code sources.

Install only in an isolated virtual environment, review or pin dependencies before running pip, and avoid opening generated reports in a browser context that has sensitive same-origin access. Treat report contents as untrusted financial display data until the HTML escaping and CDN integrity issues are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_report.py:263
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
财经日报 — {report_date} ``` ```javascript
Remediation
View remediation
`, `&`, U+2028, and U+2029, or place the data in a non-executable JSON element: ```python data_json = json.dumps(report_data, ensure_ascii=False, default=str) data_json = ( data_json.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 4. Replace `innerHTML` with `textContent` and explicit DOM construction for all remote or user-controlled values. 5. Add a restrictive Content Security Policy. Avoid allowing inline scripts if practical; otherwise use a generated nonce or script hash. 6. Add regression tests containing payloads such as closing script tags, HTML event handlers, quotation marks, ampersands, and Unicode line separators. Verify that these payloads appear only as text and never execute. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Dependency Installation Through a Relaxed Package Source

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/generate_report.py:268
Finding

Runtime Execution of Remote JavaScript Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis Every generated report loads and executes JavaScript from an external CDN when opened. Although the URL contains a Chart.js version, the report does not supply a Subresource Integrity hash. The browser therefore verifies the TLS connection but does not verify that the returned script bytes match a project-reviewed artifact. The effective executable content can change after the Skill has been audited if the CDN, package artifact, DNS path, or associated publishing account is compromised. This behavior also conflicts with the statement in `assets/README.md` that the report is self-contained and has no external runtime dependencies. ### Attack Path 1. An attacker compromises the CDN, the hosted Chart.js artifact, its publishing path, or another component capable of changing the response. 2. The user generates a financial report and opens it while connected to the network. 3. The browser requests the script from `cdn.jsdelivr.net`. 4. Because no integrity attribute is present, the browser executes any JavaScript returned successfully by that URL. 5. The malicious script runs in the generated report's browser context. 6. It can manipulate report content, create deceptive interfaces, or communicate with attacker-controlled endpoints subject to browser policy. ### Impact Assessment The remote script executes with the same document-level privileges as the report's own JavaScript. A compromised response can: - Modify all report content and financial figures. - Display phishing prompts or malicious links. - Read data present in the report. - Access browser storage and same-origin resources available to the document. - Initiate outbound netwo ...[truncated 193 chars]
Remediation
View remediation
``` The hash must be generated from and compared against the exact reviewed artifact rather than copied from an untrusted source. 3. Add a Content Security Policy restricting scripts to approved sources and preventing unexpected connections. 4. Document the external runtime dependency accurately, including its privacy, availability, and supply-chain implications. 5. Consider removing the JavaScript chart dependency entirely or rendering a static chart if interactive behavior is not essential. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill directs the agent to install packages from the network and generate an HTML file, but it does not declare any explicit tool scope or permissions for network access and file writing. This creates a governance gap where the agent may perform impactful actions without clear authorization boundaries, increasing the chance of unintended downloads, environment modification, or file creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to activate on generic market-analysis requests, not just explicit daily-report generation. Over-broad activation can cause the agent to run networked data collection and file-generation workflows unexpectedly, exposing users to unnecessary actions, costs, or confusion when they only wanted lightweight analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s user-facing title, description, and generated output are explicitly Chinese-language and Chinese-locale oriented, including the HTML lang setting and all report labels, but there is no opt-in or configurable language selection. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The overview states that the report follows Chinese stock market conventions for red/green movement, which imposes a locale-specific presentation standard. Because the skill does not offer opt-in, user choice, or a clearly justified region-specific limitation, this can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.