Back to skill

Security audit

fund-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently calls Eastmoney's fund-analysis API using a declared API key and can save the returned report locally, with no evidence of hidden or destructive behavior.

Install only if you are comfortable sending fund questions and your EM_API_KEY to Eastmoney's API. Use --no-save for sensitive analyses if you do not want Markdown reports retained locally, and keep the API key revocable and out of logs or shared files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tainted flow: 'req' from os.environ.get (line 130, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/get_data.py (reported line 141)May include surrounding context.

python
)

    try:
        with urllib_request.urlopen(req, timeout=TIMEOUT_SECONDS) as resp:
            raw_body = resp.read().decode("utf-8", errors="replace")
    except urllib_error.HTTPError as exc:
        err_body = exc.read().decode("utf-8", errors="replace") if exc.fp else ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires environment access (EM_API_KEY), performs network calls to an external service, and can write files locally, but it does not declare an explicit tool/permission scope. That creates a least-privilege gap: a host may grant broader capabilities than reviewers or users expect, reducing transparency and making misuse of secrets, outbound requests, or filesystem writes harder to govern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes a single-fund diagnostic skill but does not disclose dependency on external API credentials or environment access. Reading EM_API_KEY and refusing to run without it introduces credential handling and external-service coupling that are not justified from the stated description alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill saves fund-analysis output to a local Markdown file by default, even though this persistence behavior is not apparent from the skill description. User queries and generated financial assessments may contain sensitive or proprietary information, and silent local retention increases the risk of unintended disclosure to other local users, processes, backups, or later reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code writes analysis results to local storage by default without an explicit warning or consent flow. Even if the content is not highly sensitive in all cases, default persistence can create avoidable privacy and data-governance issues, especially for user-supplied financial questions and generated reports.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.