Back to skill

Security audit

gh-industry-deep-analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill mainly provides an industry-analysis framework, but it also requires automatic local saving, Feishu/Wiki publication, and a fixed group notification after analysis.

Install only if you are intentionally using this in the described GH/OpenClaw and Feishu workflow and are comfortable with generated reports being saved locally, added to history, published to Feishu/Wiki, and announced to the specified chat. For ordinary private industry research, require a local-only mode and explicit approval before any upload or notification.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as an industry analysis tool, but it also mandates persistence, publication, wiki movement, and group notification. Those extra actions materially expand the capability surface from analysis into data exfiltration and unsolicited dissemination without clear user consent, creating a real security and privacy risk.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Mandatory group notification is not necessary to fulfill the stated purpose of generating industry analysis, so it introduces unjustified external communication. If triggered automatically, sensitive or user-specific analysis could be sent to a fixed group destination without review or consent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers are very broad generic phrases such as an industry name or a common request to 'analyze' a sector, which can cause the skill to activate in contexts where the user did not clearly intend this specific 10-dimension framework. In an agent environment, overbroad activation increases the chance of unintended routing, response hijacking of general finance queries, and excessive generation behavior based on a loosely matched prompt.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains short, common finance terms that can match ordinary conversation and invoke a high-action workflow unexpectedly. Because this skill includes persistence and external publication steps, over-broad activation increases the chance of unintended side effects from casual mentions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation rules do not clearly distinguish between a casual industry mention and an actual request to run the full analysis workflow. Ambiguity is especially risky here because the skill is configured to perform downstream writes and outbound publication once triggered.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs saving reports to a local workspace path but does not warn the user that persistent files will be created. Silent local writes can leak sensitive research content, create compliance issues, or overwrite existing data in shared or automated environments.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Updating an existing history index file modifies local records and may corrupt or append sensitive metadata without the user's awareness. Because this changes preexisting state, it creates integrity and auditability risks beyond merely generating a report.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill requires uploading the generated report to Feishu and moving it into Wiki, which is an external transmission of potentially sensitive content. There is no explicit privacy notice, approval gate, or content review step, so analysis results could be disclosed outside the local environment automatically.

Missing User Warnings

High
Confidence
98% confidence
Finding
The required group notification sends content to a fixed external chat target without clear warning or approval. This creates a direct exfiltration path and can broadcast sensitive analysis, user context, or proprietary conclusions to unintended recipients.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description promises broad, comprehensive analysis based on 'latest data and news' but does not define clear scope boundaries, trigger conditions, or operational limits. In an agent ecosystem, overly broad skill descriptions can cause the skill to activate in unintended contexts or encourage the agent to overreach into unsupported data gathering and analysis behaviors, increasing the chance of misuse or unsafe routing.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
85% confidence
Finding
A very short trigger like '行业' can match many unrelated or low-intent inputs, increasing the chance of accidental activation. In this skill, accidental activation matters because the documented workflow includes persistent writes and outbound publication.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
85% confidence
Finding
The trigger '板块' is too generic and can appear in ordinary market discussion without indicating consent to run the full workflow. Broad matching raises the risk of unintended execution of local-save and external-sharing steps.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
85% confidence
Finding
The trigger '赛道' is a common finance term and may activate on casual discussion rather than a deliberate request. Given the skill's hidden side effects, even low-complexity trigger collisions can lead to unnecessary report generation and dissemination.

Static analysis

No suspicious patterns detected.