Back to skill

Security audit

深知可信投研(上市公司研究+政策标准洞察)

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed China A-share research tool that gathers public financial data and optional policy-search results, with no evidence of hidden exfiltration, persistence, or destructive behavior.

Install only if you want a China A-share research workflow. Be aware it can install akshare in the active Python environment, send a phone number and SMS code to DKNOWC during optional search activation, and produce model/rule-based financial research that should be verified against official filings and not treated as investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (52)

Ae1

High
Category
analysis-evasion
Content
python3 scripts/initialize.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/initialize.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/initialize.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/initialize.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/register_key.mjs send --phone <手机号>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/register_key.mjs send --phone <手机号>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/register_key.mjs send --phone <手机号>
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
本 Skill 的金融数据层依赖 akshare。`run_research.py` 会在**当前 Python 解释器**中检测依赖:已安装就直接运行;未安装时仅通过 `sys.executable -m pip` 安装到同一环境,然后继续运行。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
本 Skill 的金融数据层依赖 akshare。`run_research.py` 会在**当前 Python 解释器**中检测依赖:已安装就直接运行;未安装时仅通过 `sys.executable -m pip` 安装到同一环境,然后继续运行。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
本 Skill 的金融数据层依赖 akshare。`run_research.py` 会在**当前 Python 解释器**中检测依赖:已安装就直接运行;未安装时仅通过 `sys.executable -m pip` 安装到同一环境,然后继续运行。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/runtime_check.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/runtime_check.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/runtime_check.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/runtime_check.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/runtime_check.py
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| `比亚迪_报告.data.json` | 数据快照,可用 `render_html.py` 免调接口复渲 |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| `比亚迪_报告.data.json` | 数据快照,可用 `render_html.py` 免调接口复渲 |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `scripts/akshare_api.py` - 开源金融数据层(免 Key)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `scripts/impact_analysis.py` - 政策影响分析(传导链/财务联动)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `scripts/valuation.py` - 投资决策整合(DCF 三情景 / 相对估值 / 决策矩阵;含 --mock 离线自测)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `scripts/format_report.py` / `render_html.py` - Markdown / 可溯源 HTML 渲染(板块编号动态)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire skill documentation is written in Chinese and includes no indication that users may choose another language or that the skill is region-specific by design. The policy explicitly calls for flagging language or locale constraints when they are imposed without opt-in or justification.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description says to use the skill when the user needs broad tasks like '投资研究' or says phrases such as '研究一下某公司' and '这家公司怎么样'. These phrases overlap with common conversational requests and the file does not provide clear boundaries or exclusion conditions for when this skill should not activate.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The onboarding rule mandates exact Chinese phrasing for user-facing communication, such as only saying '开通权威检索功能' and avoiding internal terms. This imposes a specific language choice on user interaction without offering a language or locale option, which is a natural-language policy issue.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Examples like '研究一下比亚迪', '这家公司基本面怎么样', and '帮我把这家公司的政策风险排查一下' are broad enough to match ordinary user speech. The section provides examples but no explicit limitations, required context, or non-examples to prevent unintended invocation.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.