Back to skill

Security audit

Investment Advisor Digital Employee

Security checks for vulnerabilities and agentic risk

Overview

This financial-analysis skill appears purpose-aligned and has no bundled executable payload, but its metadata understates the external tools, network lookups, and report export behavior described in the instructions.

Review this skill before installing in an environment with real client or portfolio data. Require explicit approval for any external data or web lookup, keep customer identifiers and holdings minimized or anonymized, and ensure reports are previewed and approved before files are written or sent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest explicitly declares allowed-tools: [], yet the body repeatedly instructs use of external gildata-aidata, web_search, web_fetch, and command-style finx invocations. This creates a policy/specification mismatch that can cause downstream enforcement bypasses, unsafe execution assumptions, or deployment-time misconfiguration where reviewers believe the skill is non-operative while the prompt drives tool use anyway.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The security notice states there are no network calls, but the skill later depends on live market/news retrieval and explicit web/tool usage. This is dangerous because operators and users may trust the declared safety posture, while the prompt actually encourages externally connected behavior that can expose data, expand attack surface, or bypass review assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest presents the skill as reference/advisory-only, but the content includes workflows for creating and sending artifacts such as Excel reports. That gap matters because file creation and delivery are side-effecting actions with data-handling implications, and reviewers may underestimate the need for output controls, DLP review, or human approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese, and the skill body consistently instructs outputs, examples, and workflows in Chinese with no opt-in or alternative language path. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The notice frames command/config snippets as illustrative only and says there is no bundled executable material, but later modules prescribe concrete operational workflows such as generating Excel files and delivering outputs to users. While not direct malware, this inconsistency can mislead reviewers about the skill's real behavior and lead to unsafe assumptions about whether it causes side effects such as file creation or export.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.