Back to skill

Security audit

A股财报结构化拆解系统

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed A-share financial-report analysis workflow that uses public market data sources and calculation templates, with no hidden persistence or destructive behavior found.

Install this if you want structured A-share financial-report analysis. Before relying on an output, confirm the company is an A-share listing, review the cited data sources, and treat any valuation or trading implications as analysis rather than investment advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are broad natural-language phrases such as '财报分析' and '最新财报进行深度分析', which can cause the skill to activate for loosely related requests without strong scoping to A-share symbols, report periods, or user intent. This increases the chance of unintended invocation, tool overuse, and generation of authoritative-looking financial analysis in contexts where the user did not clearly request this specialized workflow.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill is tightly scoped to A-share listed companies and Chinese financial-report terminology, but the description and behavior do not clearly surface user language choice or explicit regional limitations at invocation time. This can mislead users into receiving region-specific analysis assumptions, data-source priorities, and output conventions that are inappropriate for other markets or languages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.