Back to skill

Security audit

stock-analysis-and-review-wechat

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent stock-review and WeChat reporting tool, but it asks users to create recurring main-agent tasks that can repeatedly process portfolio data, update memory, and send reports without strong lifecycle or recipient controls.

Install only if you want a Chinese-language stock review workflow with WeChat integration. Before enabling automation, confirm every cron task name, schedule, target agent, memory-write behavior, and WeChat recipient/account; prefer one-time reports unless you intentionally want recurring monitoring, and remove tasks you no longer use.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:115
Finding

Recurring Cross-Session Agent Tasks Create System Persistence

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s description, headings, instructions, and examples all require Chinese comprehension, effectively forcing a specific language for use of the skill. The document does not offer an alternative language option or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives conflicting guidance about cron delivery configuration: earlier it says not to manually specify delivery accountId/to and to rely on announce+last, while the later WeChat push section states accountId and to are required. This inconsistency can cause misconfigured scheduled pushes, failed notifications, or accidental delivery to an unintended last-active channel, which is risky in a tool handling investment summaries and account-linked messaging.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill includes clear capabilities that imply network access, file reads, and file writes, such as fetching market data, updating MEMORY.md, and integrating scheduled tasks, but it does not declare an explicit tool scope or permissions boundary. This creates a least-privilege gap: a host may grant broader access than users expect, increasing the risk of unintended data exfiltration, unsafe file modification, or overbroad execution when the skill is run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and all operational guidance are written entirely in Chinese, and the file does not indicate that users may choose another language or that the skill is restricted to a China-specific audience for compliance reasons. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users may opt into this language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and all instructional content are written entirely in Chinese, and the examples explicitly assume a China-specific timezone and market context. Because the document does not state that the skill is region-specific or offer an opt-in language/locale choice, it appears to enforce a specific language/locale policy through natural-language instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance instructs the agent to push stock review and portfolio information to WeChat, an external messaging channel, but does not clearly require explicit user consent or warn that sensitive financial data will leave the local analysis context. In this skill, the report may include holdings, gains/losses, account-linked identifiers, and review notes, so silent transmission increases privacy and data disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation and output strings that assume Chinese as the only language, beginning with the module docstring and continuing throughout the report template. The policy requires flagging language or locale constraints when they are forced without user opt-in and not clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language descriptions and messages entirely in Chinese, including the module docstring and runtime diagnostics, with no indication that language selection is configurable. Under the policy rule for language/locale, forcing a specific language without user opt-in is a violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function claims to verify the WeChat/OpenClaw plugin version but always returns a hardcoded success value, so callers may rely on a security or compatibility check that never actually occurs. In this skill, that can cause reports to be sent through an unverified or incompatible plugin, weakening trust assumptions and potentially masking operational or supply-chain issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON manifest/template contains user-facing natural-language fields such as description, notes, and entry conditions entirely in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.