Back to skill

Security audit

point-figure

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable educational charting skill with some assertive trading-language guidance that users should treat as informational, not as personalized financial advice.

Before installing, understand that this skill teaches a trading-chart method and uses firm language about signals. Treat outputs as educational support for your own analysis and risk controls, not as personalized investment advice or automatic trading instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill gives prescriptive trading instructions such as immediately closing positions on signals and executing buy/sell actions, but does not clearly frame them as educational content rather than personalized investment advice. In the context of a trading skill, users may over-rely on these directions and incur real financial losses, especially because the language emphasizes discipline and immediacy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill repeatedly documents point-and-figure as having no time axis and recording only price movement, but L041 says '瑞士法郎可用 9 天为转行、棉花用 1 天' and L077 again asks the user to choose a '转行周期'. That is not merely incomplete detail; it actively reintroduces time-based periods into documentation that otherwise insists time is ignored, so the documented intent conflicts with itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The expected behavior is written as an imperative requiring the skill to respond in Chinese ('讲…逻辑'), and the surrounding test prompts and notes are all Chinese-only. This creates a natural-language policy concern because it appears to force a specific language without any user opt-in or documented regional justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

This line specifies expected output entirely in Chinese and directs the skill to deliver policy-like guidance in that language only. Because the file does not indicate that the skill is region-specific or that users can choose another language, it may violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.