Back to skill

Security audit

国泰海通证券-灵犀研报搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill broadly matches a protected research-report search tool, but it needs Review because it handles API keys and device identifiers in under-scoped ways and includes instructions that try to limit inspection and force response text.

Install only after reviewing the source and accepting that this skill stores an API key locally, may ask for API-key material through chat, sends credentialed requests to configured gateways, and uses a MAC-derived device identifier during authorization. Prefer a version that uses a secure secret handoff, random short-lived device nonces, a fixed gateway allowlist, and clearer inspection-friendly instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Agent Inspection and Output Hijacking Through Skill Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill-entry.js:1
Finding

Undisclosed MAC-Address-Derived Device Fingerprinting

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill-entry.js:1
Finding

Untrusted Gateway Configuration Can Redirect Credentials and Queries

Content
View full analysis
{ let _=ie.request({ hostname:v.hostname, port:v.port||443, path:v.pathname, method:"POST", headers:re, rejectUnauthorized:!0 },I=>{ let P=""; I.on("data",R=>{P+=R}), I.on("end",()=>{ try{se(JSON.parse(P))} catch{T(new Error(`解析响应失败: ${P}`))} }) }); _.on("error",T), _.write(N), _.end() }) } ``` ### Technical Analysis The skill accepts a gateway configuration path from `GTHT_GATEWAY_CONFIG`. It also searches locations derived from the process working directory. The res ...[truncated 2465 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a narrowly scoped research-report search tool, but its instructions also cover credential handling, local file storage, authorization state management, and generic gateway tool invocation. That mismatch weakens user and agent trust boundaries: a caller may authorize or invoke broader capabilities than expected, increasing the chance of over-privileged execution and unintended data exposure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell the agent to have the user send an API key in chat to complete authorization, creating a direct natural-language credential exfiltration path. This is especially dangerous in an investment-research skill because users may trust the 'official' framing and disclose long-lived credentials that can be logged, replayed, or reused to access protected services.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The entrypoint implements MCP client behavior and can invoke remote tools/gateways via sendJsonRpcRequest and callTool, yet this capability is flagged as undeclared. Hidden remote-call capability is dangerous because it allows network-mediated actions beyond a simple report-search interface and expands the attack surface substantially.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The entrypoint implements MCP client behavior and can invoke remote tools/gateways via sendJsonRpcRequest and callTool, yet this capability is flagged as undeclared. Hidden remote-call capability is dangerous because it allows network-mediated actions beyond a simple report-search interface and expands the attack surface substantially.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The authorization instructions explicitly tell the user to copy or send an API key to the agent to complete authorization. Asking users to disclose bearer credentials to an intermediary is a serious anti-pattern because it normalizes secret sharing and gives the skill/operator direct access to credentials that can be replayed elsewhere.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction to use this skill whenever users query report data is overly broad and may capture requests that are only tangentially related to research reports. Because this skill includes auth flows and external calls, ambiguous activation can unnecessarily expose users to credential collection and network operations they did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction to use this skill whenever users query report data is overly broad and may capture requests that are only tangentially related to research reports. Because this skill includes auth flows and external calls, ambiguous activation can unnecessarily expose users to credential collection and network operations they did not explicitly request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill first declares a strict file-access boundary, then later instructs the agent to search multiple parent directories for the API-key file. Contradictory boundary rules create ambiguity that can cause the agent to read or write sensitive credential files outside the intended scope, undermining containment guarantees.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill asks users to provide an API key for authorization but does not warn that the key is sensitive or instruct them to use a secure channel. In a conversational agent setting, that omission materially increases the chance that users will paste credentials into chat, where they may be logged, retained, or exposed to downstream systems.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
> **此区域供业务同事发挥,用于定义具体的服务意图与话术引导。**


| 场景分类           | 典型用户问题 (Intent)                     | 业务逻辑指导                                                                                                                                                                                                       |
| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **研报搜索**     | "最新宏观经济研究报告","SH600000开盘价是多少?"                  | 调用 `search-research-report`。                                                                                                                                                                         |
|

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
| 场景分类           | 典型用户问题 (Intent)                     | 业务逻辑指导                                                                                                                                                                                                       |
| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **研报搜索**     | "最新宏观经济研究报告","SH600000开盘价是多少?"                  | 调用 `search-research-report`。                                                                                                                                                                         |
|

### 问句示例

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file is primarily an authorization/token-management CLI and generic MCP caller, not a narrow research-report search implementation as described in the metadata. This mismatch is security-relevant because users and reviewers may grant trust or permissions based on the stated purpose while the code performs broader credential and network operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code derives a device identifier from the local MAC address and combines it with timestamp/random data to drive authorization. Collecting hardware-derived identifiers is unnecessary for a report-search skill and creates device fingerprinting and privacy risk if logged, stored, or transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill writes the API key to a shared/local JSON file on disk without any meaningful warning, consent flow, or protective controls. Persisting credentials this way increases the risk of token theft from other local users, backups, logs, or adjacent tools that can read the shared path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

After successful authorization polling, the code logs the raw server response, which may contain the API key or closely related sensitive authentication material. Emitting secrets to stdout is dangerous because terminals, shell history wrappers, CI logs, and agent transcripts may retain them far beyond the intended session.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

L101 states the agent must never call the native system shell and must always use node commands, but L103-L125 then provide execute_command separator rules and PowerShell-native file existence checks. That documentation directs shell usage patterns that conflict with the earlier 'must always use node' instruction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The help text, prompts, and operational status messages are presented exclusively in Chinese throughout the CLI output. This imposes a specific language/locale on users without offering opt-in, selection, or documentation that the skill is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.