Back to skill

Security audit

congress-stock-tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent public-data tracker for U.S. congressional stock trades and does not show hidden, destructive, persistent, or credential-seeking behavior.

Before installing, understand that the skill fetches public congressional trading data from the web and may save JSON or CSV files where requested. Treat its market analysis as research only, not investment advice, and choose output paths deliberately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a networked data-fetching script and writes output files, but the manifest does not declare any tool scope or allowed-tools restrictions. This creates an over-permissioning/ambiguity risk: a host agent may allow broader filesystem or network access than intended, making misuse, SSRF-like fetch behavior, or unintended file writes harder to constrain and audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and user-facing documentation are entirely in Chinese, and the skill presents its workflow and output requirements only in that language. There is no indication that language is user-selectable or that the Chinese-only constraint is required for a region-specific compliance purpose, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document's title, instructions, templates, and required output language are all in Chinese, which effectively forces a specific language for use of the skill. Under the policy, language restrictions should either be optional for the user or clearly justified as a region- or locale-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

该文件全文以中文呈现,未见任何说明允许其他语言、提供语言选项,或声明这是面向特定中文用户群的区域化资料。按规则,未经用户选择而固定单一语言可能构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request headers force Accept-Language: en-US,en;q=0.5, which imposes a specific language/locale in network interactions. The file does not offer a user opt-in or configurable locale, and there is no documented region-specific reason for this restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.