Back to skill

Security audit

wealth-innovation-briefing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese wealth-management briefing generator with some dependency and browser-hardening caveats, but no evidence of credential theft, deception, exfiltration, or destructive behavior.

Install only if you want a Chinese wealth-management briefing workflow that searches public web sources and writes local HTML/PDF outputs. Prefer running it in a dedicated project folder or virtual environment, pin Playwright before use, and avoid --no-sandbox unless the renderer is isolated.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/convert_pdf.py:4
Finding

Unpinned Playwright Dependency Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
``` 2. Generate and verify hashes for all resolved packages, then install with: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Commit the lock or requirements file to the repository and update both `README.md` and `SKILL.md` to reference it instead of installing an unconstrained package. 4. Use a trusted, explicitly configured package index and prevent unreviewed fallback indexes or mirrors. 5. Run dependency vulnerability and provenance checks during updates. Review dependency changes before regenerating the lock file. 6. Install and run the converter in a dedicated virtual environment under a non-administrative account. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/convert_pdf.py:27
Finding

Chromium Renderer Runs with Its Security Sandbox Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 18)May include surrounding context.

text
# Secrets
*.token
.env

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description mandates producing a Chinese-language briefing format ('金融创新简报') and the rest of the file consistently prescribes Chinese content and formatting, but it does not offer the user a language choice. This is a natural-language locale policy issue because the skill appears to enforce a specific language by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The '何时使用' section lists broad request patterns such as '每日/每周金融创新简报' and '财富管理动态' without defining what kinds of requests should not invoke the skill. These phrases could overlap with general research or reporting requests, making invocation scope ambiguous.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill that produces a vertical A4 poster PDF for reporting and email sharing. This implementation only writes briefing.html to disk and does not perform any PDF rendering or export, so the actual deliverable differs from the stated output format.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template explicitly requires the body to include Chinese-language content elements such as '时间 + 具体公司 + 动作/数据 + 为什么值得关注', and the file overall is authored as a fixed Chinese-language template. This appears to impose a specific language/locale without any opt-in, alternative, or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The markdown states the skill will automatically collect updates across multiple domains, which implies network access, and elsewhere describes producing a PDF artifact. The README provides usage steps but does not include any user-facing warning that the skill will fetch external content and create local output files that may affect privacy or the filesystem.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.