Back to skill

Security audit

Financial AI Strategy Architect

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executing financial AI strategy reference skill with clear advisory limits and no privileged behavior.

Install this as an advisory reference only. Do not treat its outputs as financial, legal, insurance, or regulatory advice without qualified human review, and ask for another language if Chinese-first output is not desired.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
The metadata states 'Language: 中文为主,英文关键术语保留', which imposes a language preference in natural-language instructions. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified as region-specific.

Static analysis

No suspicious patterns detected.