Back to skill

Security audit

Hutian Opc Ma Match

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Chinese M&A matching knowledge pack, but it includes high-risk shell-company outreach guidance that tells users to obscure buy-shell or control-transfer intent.

Install only if you need China/Hong Kong M&A matching research and can keep all use under legal, securities-compliance, and privacy review. Do not use the included pretext-based outreach scripts; verify contact data from official filings, use truthful purpose disclosure, avoid insider-information solicitation, and handle any diligence materials through authorized secure channels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (47)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document explicitly instructs operators to conceal the true purpose of contact by posing as a generic 'strategic cooperation' party and avoiding direct mention of shell acquisition or control transfer. In an M&A matching skill, this crosses from analysis into deceptive operational guidance, increasing legal, compliance, and reputational risk and enabling manipulative outreach to public-company personnel.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains ready-to-use scripts for probing shell-sale willingness while masking the real objective, including staged follow-up language and techniques for eliciting sensitive signals. This is dangerous because it standardizes deceptive engagement and can facilitate improper influence, selective-information gathering, or misleading communications with listed-company representatives.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section provides an execution playbook for acquiring control of listed shells, including specific transaction structures, threshold tactics, pricing ranges, and sequencing. That exceeds the stated scope of matching and assessment and operationalizes a sensitive control-transfer process that can be misused for evasive or non-compliant transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents a script named update_knowledge_base.py for bulk knowledge-base updates, which implies writes to persistent data. The README provides usage examples but does not warn users that running it may modify or overwrite knowledge-base contents, affecting system integrity or data state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README gives a concrete command to run python3 update_knowledge_base.py --batch 2024_Q4 but does not disclose that executing it may change persistent knowledge-base data. For markdown files, operations that can affect user data or system integrity should be accompanied by clear warnings.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guidance recommends a progressive deception pattern: establish rapport under a benign cooperation pretext, then infer shell-sale intent from signals while withholding true motives. In the context of a listed-company M&A skill, this is especially risky because it trains users to manipulate communications around sensitive corporate-control matters.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These templates instruct users to begin with innocuous 'cooperation' framing and later escalate toward control-transfer topics based on the target's reactions. That is a clear multi-step deception workflow and is more dangerous here because the subject matter involves public issuers, insiders, and potentially market-sensitive transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document aggregates named corporate contacts, direct phone numbers, and email addresses for outreach in a sensitive M&A shell-resource context, but provides no compliance, privacy, or lawful-use guardrails. Even if some data may be from public filings, centralizing it with recommendation scores and outreach guidance materially lowers the barrier to targeted solicitation, harassment, or improper deal-sourcing activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file provides concrete outreach scripts for approaching listed companies about sensitive strategic transactions without warning about legal, compliance, deception, or reputational risks. In the M&A shell-matching context, this can facilitate misleading pretexting, unauthorized investor-relations contact, and problematic communications around restructuring or control transactions.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The staged contact guidance explicitly recommends building trust under a softer pretext and then probing for '卖壳/重组' intent, which is a form of manipulative social engineering. This is especially dangerous because the skill is designed for identifying acquisition targets among listed companies, so the narrative structure is directly aligned to eliciting sensitive strategic information that the counterparty may not have intended to disclose in that context.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to avoid explicit mention of '买壳' and instead use euphemisms like '战略合作' or '产业整合' is an intentional obfuscation of the real objective. That makes the content more dangerous in this skill context because it teaches users how to evade scrutiny and obtain engagement under misleading framing during highly sensitive M&A-related outreach.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report labels the first tier as financially clean and directly approachable, yet includes a company for which it also documents serious disclosure violations, hidden agreements, related-party guarantee issues, and pending regulatory penalties. That inconsistency can mislead users into underestimating legal and regulatory risk when selecting targets for sensitive M&A or control-transfer activity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file goes beyond market analysis and provides named points of contact, phone numbers, email addresses, and explicit outreach sequencing for approaching listed companies about control-transfer or 'shell' transactions. In this skill context, that materially enables direct operational targeting and compliance-sensitive contact workflows, increasing the risk of misuse for market manipulation, circumvention of disclosure norms, or inappropriate solicitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document combines public business contact information with step-by-step guidance for initiating sensitive control-transfer discussions, but lacks strong warnings about securities compliance, privacy handling, solicitation rules, and recordkeeping. In an M&A matching skill, this omission makes the content more dangerous because users are nudged toward real-world outreach without adequate legal or ethical safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This form solicits highly sensitive business data, including financials, customer concentration, shareholder structure, core technical staff details, IP, and proprietary R&D information, but provides no concrete guidance on secure submission channels, retention limits, access controls, encryption, or data minimization. In an M&A diligence context, this creates a realistic risk of unnecessary oversharing, insecure handling, and downstream leakage of trade secrets or personal data if the document is copied, emailed, or stored improperly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The matching keywords are broad, generic industry terms without explicit inclusion/exclusion rules, thresholding, or disambiguation logic. In an M&A matching skill, this can cause over-triggering on ordinary新能源/投资 content, producing incorrect candidate matches, noisy outputs, and potentially misleading business recommendations at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plan explicitly includes collecting '联系方式(如有)' for Hong Kong shell resources without any accompanying privacy, legal basis, access-control, or data-handling requirements. In an M&A matching skill, contact details may include personal information about brokers, executives, or intermediaries, creating unnecessary privacy and compliance exposure if gathered or stored indiscriminately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file includes a data export capability, including report and JSON outputs, which could affect data handling and downstream distribution. Although the document later includes general compliance guidance, this specific behavior is not accompanied by an explicit warning at the point of use about reviewing export scope, permissions, or sensitive content before export.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing instructions and descriptions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill manifest and instructions are presented exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该参考文件全文以中文撰写,且未说明是否允许用户选择其他语言或地区版本。根据规则,若技能内容强制单一语言而没有用户选择或明确、合理的地区性限定,属于自然语言层面的语言/地区策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language instructions, examples, and descriptions are all presented in Chinese, which can amount to a language policy constraint when no user opt-in or alternative is offered. The file does not indicate that the skill is region-specific or otherwise justified to require Chinese only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

该 markdown 文档内置了中文电话话术,并在L064明确要求只用特定表述进行包装,属于自然语言行为指引。虽然主要是业务话术,但全文未说明这是面向中文场景的限定模板,也未提供语言/地区选择,存在轻微的语言/locale 强制倾向。

Content

No source excerpt is available for this finding.

Ssd 4

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although less explicit than earlier sections, this guidance still recommends using ostensible business cooperation as a probe for latent shell-sale demand and reading reactions as covert signals. The lower severity reflects its more indirect form, but it still promotes deceptive elicitation outside the skill's justified analytic scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.