Back to skill

Security audit

Alphagbm Theme Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AlphaGBM integration for managing investment-theme baskets, with expected API-key and service-side theme storage behavior.

Install only if you intend to let the agent use your AlphaGBM API key to read and manage saved investment themes. Confirm create, update, and especially delete requests before allowing changes, and be aware that broad words like theme or basket may activate this skill in finance conversations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises invocation on very generic terms like "主题 / theme / basket / 篮子 / 板块", which are common in finance conversations and can cause the skill to activate when the user did not intend theme-management actions. In an agent setting, over-broad triggering can lead to unintended API calls, accidental creation/modification of themes, or disclosure of portfolio-theme data in the wrong conversational context.

Static analysis

No suspicious patterns detected.