Back to skill

Security audit

雪球网互动操作

Security checks for vulnerabilities and agentic risk

Overview

This skill is for operating a Xueqiu account, but it can perform public account actions from broad triggers without clear confirmation safeguards.

Review before installing. Use it only if you are comfortable letting an agent act through your Xueqiu account, and require explicit confirmation of the exact platform, target post, action, and final text before any publish, repost, comment, like, or favorite is submitted.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is triggered by broad everyday phrases like '点赞', '评论', '转发', and '发个观点', which can easily overlap with normal conversation or quoted text. Because this skill performs real account actions on xueqiu.com, ambiguous invocation raises the risk of unintended likes, comments, reposts, or publishing under the user's identity.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document enables actions that modify the user's account state and public presence—posting, commenting, reposting, liking, and bookmarking—without a prominent requirement for explicit user confirmation, preview, or risk disclosure. In this context, accidental or coerced execution could cause reputational harm, unwanted public statements, social-engineering abuse, or irreversible actions performed as the user.

Static analysis

No suspicious patterns detected.