Back to skill

Security audit

Investment Committee

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its investment-analysis purpose, but it can publish and store sensitive investment reports and gives specific trade guidance without clear confirmation or risk controls.

Review before installing. Use it only if you are comfortable with market-data/web lookups, Chinese-language investment reports, local report archives, and potential Discord posting. Do not include sensitive account details or private portfolio information unless the runtime requires explicit confirmation before sharing or storing the report. Treat its position sizing, stop-losses, and target prices as educational analysis, not personalized financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior promises a multi-agent investment committee, independent expert analysis, verdict synthesis, and operational recommendations, but the finding indicates the implementation mainly performs external price fetching and lacks the stated analysis pipeline. This kind of mismatch is dangerous because users may place undue trust in authoritative-seeming outputs without realizing the skill's actual capabilities and data provenance are much narrower than advertised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes network-capable behavior (fetch_price.py against stooq.com and web_search) but does not declare any tool scope or allowed tools. This weakens least-privilege controls and makes it harder for users or the platform to understand and constrain external data access, especially in a finance-related skill that may influence decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该描述把“帮我分析BTC”等自然日常表达直接作为适用场景示例,但没有限定必须在何种上下文、以何种明确命令触发技能。对于 markdown 技能说明而言,这类宽泛短语容易与普通对话重叠,增加误触发风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

“输出中文裁决报告”表明技能默认强制使用特定语言,但文档没有说明这是可选项,也未提供按用户偏好切换语言的机制。按照语言/地区策略,这属于未获用户选择即施加语言限制的自然语言政策问题。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatically sending the generated report to the current Discord channel expands the data flow beyond analysis into external distribution. In context, users may provide holdings, P/L status, and portfolio details; broadcasting that to a channel can leak sensitive financial information to unintended recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation includes writing outputs to Discord and local history without clearly notifying the user at the point of use. Hidden or under-disclosed data writes are dangerous because users may reveal sensitive holdings or trading intentions assuming the interaction is ephemeral, when in fact it is distributed and retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to output concrete trading actions, position sizing, stop-loss levels, and target prices without any risk disclosure, suitability check, or limitation on personalized financial advice. In an investment-advice context, this materially increases the chance that users act on authoritative-seeming recommendations and suffer financial harm, especially because the persona emphasizes confidence, concentration, and aggressive sizing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill specification, persona, framework, and output requirements are written to operate in Chinese, with no indication that the user may choose another language or locale. Under the policy rule for natural-language violations, this constitutes a language/locale constraint without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill content is written entirely in Chinese and its output requirements assume Chinese responses without indicating any user-language negotiation. In a multi-user or multilingual agent environment, this can degrade usability, cause misunderstandings of financial guidance, and reduce the user's ability to verify or safely act on investment analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is written entirely as a prescriptive Chinese-language prompt and does not provide any user-language negotiation or documented locale constraint. In a general-purpose investment-analysis skill, this can reduce accessibility, cause user misunderstanding of financial guidance, and create prompt rigidity that overrides user preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written as mandatory Chinese-language output rules and does not provide any user-language or locale fallback. In an agent setting, this can override user preferences, reduce accessibility, and create unsafe misunderstandings if users rely on the output for financial decisions but cannot fully understand the recommendation details, risks, or position-sizing instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language instructions and usage description are entirely in Chinese, which can impose a specific language on users without any opt-in or alternative locale. Under the policy, language constraints should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Archiving reports into workspace history files creates persistent storage of potentially sensitive investment positions, recommendations, and performance context. Even if local to the workspace, unnecessary retention increases exposure to later unauthorized access, cross-task leakage, or misuse of historical financial data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template uses Chinese throughout and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

All natural-language instructions in the skill are written to produce a Chinese-language persona and output format, with no opt-in or alternative language option. This is a locale/language policy concern because the file imposes a specific language by default rather than allowing user preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file makes an HTTP request to stooq.com to transmit the requested ticker symbol and timing parameters, but the runtime code provides no confirmation prompt, logging, or printed notice that an external service is being contacted. The top-level docstring names the data source, but there is still no user-facing disclosure at execution time for the outbound network access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.