Back to skill

Security audit

Research Report Hunter / 行业研报猎手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed report-finding workflow that writes approved reading lists and evidence records to JishuDB without hidden code or bypass behavior.

Before installing, make sure you are comfortable granting JishuDB write access for the selected knowledge base and with report metadata, excerpts, and reading-list records being retained there. Override the default geography if your research should not start from mainland China-focused discovery sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes 'mainland China as a starting geography' as a default without explicit user opt-in. This can bias search scope, alter results in a politically or regionally sensitive way, and may cause the agent to send queries or route discovery through a jurisdiction the user did not request, creating privacy, compliance, and accuracy risks.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
85% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
| Use when | The user needs relevant reports to read, with dates and availability checked. |
| Delivers | Ranked reading list, report cards, citations, discovery log, and JishuDB records. |
| Requires | JishuDB write access, authorized browsing/search, and local text output. |
| Does not | Guarantee free PDFs, bypass access restrictions, or claim unread reports were inspected. |

## Use this skill when

Static analysis

No suspicious patterns detected.