Back to skill

Security audit

Privora · A股/港股/黄金/基金 多资产 量化分析 · 量化回测 · 模拟盘 · 实时告警 · 风险监控 · Python 策略 · AI Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill appears legitimate for Privora investment workflows, but it gives agents broad platform-changing authority, including some persistent scheduler replacements without enforced confirmation.

Install only with a dedicated least-privilege Privora token. Start with read-only scopes, add write scopes only for a specific workflow, and avoid granting scheduler, datasource, process, webhook, portfolio/trading, or wildcard scopes to an autonomous agent unless you are comfortable with persistent remote changes. Treat schedule.job.depends.save and schedule.job.plugins.save as destructive replacements: list current entries first and submit the complete intended state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:738
Finding

Destructive scheduler configuration replacement lacks an enforced confirmation gate

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 738–742
Vulnerability Type: Destructive persistent configuration change without enforced confirmation
Risk Level: Medium

Relevant snippet:

markdown
| `schedule.job.depends.save` | POST | Full replacement of the job dependency list (existing entries are deleted before new entries are written, without a confirmation handshake; omitted dependencies are silently cleared). Supports OR/AND grouping through `dependGroup`. | 🟡 |
| `schedule.job.plugins.list` | GET | Lists plugins bound to a job, by jobCode. | 🟢 |
| `schedule.job.plugins.save` | POST | Full replacement of the job plugin list (existing entries are deleted before new entries are written, without a confirmation handshake; omitted bindings are silently cleared). | 🟡 |

Technical Analysis

The Skill exposes schedule.job.depends.save and schedule.job.plugins.save through its generic API dispatcher. Both operations use full-replacement semantics: the platform deletes existing persistent configuration and then writes the supplied array.

Unlike the separately documented confirmRequired:true operations, these endpoints do not enforce a two-step confirmation handshake. The documentation recommends listing current bindings before constructing a replacement, but this is only procedural guidance. Neither the execution wrapper nor the documented server behavior requires evidence that the caller retrieved and reviewed the current configuration.

Consequently, an Agent with the relevant write scope can directly submit an incomplete or empty replacement array. An omitted dependency or plugin is treated as an instruction to delete it, rather than as an unchanged field. This creates a reachable destructive-operation risk even without malicious project intent.

Attack Path

  1. The operator grants an Agent the scope required to manage scheduler dependencies or plugins.
  2. The Agent invokes `sche ...[truncated 1357 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add these full-replacement operations to the server-enforced confirmRequired:true workflow.
  2. Return a preview of entries that will be added, changed, and deleted before accepting confirmation.
  3. Require an expected configuration revision or ETag and reject stale replacement requests.
  4. Provide incremental add, update, and delete endpoints so routine changes do not require destructive replacement.
  5. If full replacement remains necessary, require an explicit destructive flag for requests that omit existing entries or supply an empty array.
  6. Enforce the protection server-side; documentation instructing callers to list current values first is not an adequate authorization or confirmation boundary.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (62)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full investment agent execution platform centered on invoking /agent/skills/execute and supporting numerous finance-specific capabilities. The supplied code chunk instead implements a standalone shell utility for skill discovery: listing all visible skills and describing a specific skill via GET /agent/skills. Its notable behavior is security hardening around destination validation and safe curl header injection, not investment analysis or workflow execution. This is a material description-behavior mismatch because the primary purpose differs: discovery/metadata inspection versus execution of finance workflows.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 286)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 426)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 433)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 513)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 533)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 545)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 552)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 563)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 604)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 607)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 657)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 706)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1015)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1039)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1048)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1109)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1120)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1926)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1938)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1994)May include surrounding context.

md
**Agent 侧用 `lg_agent_exec.sh` 调用同理**(v1.0.45 起支持命名参数扁平写法,不用手拼 JSON):

Static analysis

No suspicious patterns detected.