Back to skill

Security audit

HK IPO Parameter Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real HK IPO tool, but it ships and exposes much broader financial-data, profile, network, and persistence features than its parameter-manager description discloses.

Review before installing. Treat this as a full HK IPO decision-support runtime, not just a parameter manager: it may store financial preferences and review history locally, activate scoring versions, cache market data, and make requests to third-party finance sites. Install only if you are comfortable with those broader capabilities and use it with explicit commands rather than giving it open-ended authority.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (39)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill declares no permissions, yet the bundled runtime appears capable of reading environment variables, accessing and modifying local files, and using the network. This creates a trust and review gap: users may invoke what looks like a narrow parameter-management skill while actually granting a much broader execution surface than the manifest discloses.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented purpose is limited to HK IPO parameter version management, but the underlying runtime reportedly includes extensive unrelated capabilities: external data fetching, recommendation generation, watchlist/profile management, imports/exports, and persistent state changes. This mismatch is dangerous because reviewers and users may authorize the skill under false assumptions, while the runtime can perform materially broader actions including network access and modification of local state.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The reference guide exposes a much broader operational surface than the skill claims, including external market-data collection, prediction logic, and operational utilities. This scope mismatch can mislead downstream agents or reviewers into invoking capabilities outside the declared parameter-management role, increasing the chance of unauthorized data access, unintended actions, or prompt-surface abuse through undocumented tool usage.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Documenting arbitrary CLI workflows in a skill that is supposed to manage scoring parameter versions materially increases risk because agents may treat shell execution as an approved capability. That can enable command execution paths, external data retrieval, and unintended file or environment interaction beyond the skill's stated scope, which is especially dangerous in agentic environments.

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
Cache-clearing and cache-testing commands are operational controls unrelated to parameter version management and may let an agent alter runtime state or degrade service behavior. In an agent context, even seemingly harmless maintenance commands can disrupt availability, invalidate assumptions, or interfere with other workflows if invoked without explicit authorization.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This package initializer exposes a large set of IPO market-data, document-retrieval, and cache-management functions that materially exceed the declared skill purpose of managing Hong Kong IPO scoring parameter versions. That mismatch increases the agent's effective authority and creates an unnecessary capability surface, enabling data access and stateful operations that a caller or orchestration layer may not expect from this skill.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
Exporting cache mutation operations such as setters and cache-clearing functions gives this skill write/delete capabilities unrelated to its stated parameter-management role. In an agent setting, unexpected state mutation can be abused to poison cached data, erase operational state, or interfere with other workflows that rely on shared cache contents.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The initializer exports HKEX document and broad market-data retrieval functions, including prospectus/document access, despite the skill being described as a parameter manager. This unjustified access broadens available external data channels and may let an agent use the skill for unintended collection or enrichment tasks outside its approved scope.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The module docstring explicitly labels the package as a general Hong Kong IPO data tool, which contradicts the manifest's narrower parameter-manager purpose. While a docstring alone is not exploitable, this inconsistency is a strong indicator of scope drift and makes it more likely that reviewers, agents, or policy layers will misclassify the true capabilities being exposed.

Description-Behavior Mismatch

High
Confidence
92% confidence
Finding
The file implements a broad operational CLI for IPO data retrieval, market analysis, sponsor statistics, and user profiling, which materially exceeds the declared skill purpose of parameter-version management. This kind of scope mismatch is dangerous because it can expose unexpected capabilities to an agent or user, defeating least-privilege assumptions and enabling collection or processing of sensitive user and market data outside the advertised trust boundary.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The profile command reads a local user-profile.yaml and uses it to drive IPO affordability and recommendation-oriented analysis, despite this behavior being unrelated to parameter management. In an agent-skill setting, undisclosed access to local profile data increases privacy risk and can cause the agent to act on sensitive financial preferences or capital information the user did not knowingly authorize for this skill.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
This file adds broad live market-data scraping, detailed IPO lookups, and CLI access that are not aligned with the stated skill purpose of managing parameter versions. In an agent setting, this expands the tool’s capability boundary to unrestricted external data retrieval, creating unnecessary data-exfiltration, prompt-to-network pivoting, and supply-chain risk from parsing untrusted remote HTML.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The code performs unjustified external web scraping for a tool described as parameter management, meaning the implementation can reach outside its expected trust boundary and ingest untrusted content from a third-party site. In practice, this can enable hidden capability creep, reduce auditability, and expose the agent runtime to network-based abuse or malicious content changes from the scraped source.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
This file implements live A+H share lookup and pricing via Sina/Tencent APIs, which is unrelated to the declared skill purpose of managing HK IPO scoring parameter versions. Capability mismatch is dangerous because it introduces hidden data-exfiltration and off-scope network behavior that operators would not expect from a parameter-management skill, increasing supply-chain and trust-boundary risk. In this context, the mismatch makes the issue more suspicious, not less, because financial market lookups are unnecessary for the advertised function.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The code performs outbound HTTP requests to third-party finance endpoints based on user-influenced company names, despite the skill description not justifying any external network access. Even if the requests are over HTTPS and appear read-only, they leak usage patterns and queried entities to external services, create dependency on unvetted remote data, and expand the attack surface through hidden egress. The mismatch with the stated parameter-management context makes this more dangerous because operators are less likely to have approved or monitored such traffic.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file materially exceeds the declared skill purpose of managing HK IPO scoring parameter versions and instead implements broad external market-data collection, including detailed IPO, grey market, ranking, and broker intelligence retrieval. In an agent environment, this kind of scope drift is dangerous because it silently expands the skill’s authority, data exposure, and operational surface area beyond what a caller or reviewer would reasonably expect from the manifest.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The ranking, sponsor-history, and participation-analysis capabilities provide external market intelligence unrelated to parameter-version management, creating an unjustified expansion of functionality. Such hidden analytical features can be abused for unauthorized intelligence gathering or recommendation shaping, especially when embedded in a skill that users may trust for narrow configuration management only.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file's behavior materially diverges from the declared skill purpose: instead of managing parameter versions, it implements a separate IPO allotment prediction engine. In an agent-skill environment, this kind of scope drift is dangerous because it can bypass review assumptions, expand the effective capability surface, and cause downstream components or users to rely on unapproved financial decision logic.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The embedded CLI exposes an end-user prediction workflow that is unrelated to the stated parameter-management function. Extra executable entrypoints increase attack and misuse surface, make hidden functionality easier to invoke outside intended orchestration, and can lead to unreviewed operational use of sensitive financial estimation code.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This code performs live network retrieval from an external site even though the skill is described as managing Hong Kong IPO scoring parameter versions. That mismatch expands the skill's effective capability beyond its declared scope, creating supply-chain and data-exfiltration risk because a seemingly harmless parameter-management skill can unexpectedly reach out to third-party infrastructure and ingest untrusted content.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
These public functions expose sponsor-ranking and sponsor-statistics retrieval behavior unrelated to parameter version storage, activation, comparison, or inspection. Hidden or undeclared functionality is dangerous in agent skills because it can be invoked by higher-level orchestration to perform actions users and reviewers did not authorize, undermining least privilege and trust boundaries.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The imports and constants establish a scraping capability against an external website despite the stated purpose being parameter-version management. In this context, unjustified network access is a security concern because it increases attack surface, introduces dependence on untrusted remote content, and can bypass organizational expectations about what the skill is allowed to do.

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
This code performs live web scraping from futunn.com, which is outside the declared scope of a parameter-management skill. That creates an unexpected data-exfiltration and supply-chain surface: the skill can make outbound requests to a third party and ingest untrusted remote content, increasing privacy, integrity, and governance risk.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
This function adds recent IPO performance analytics behavior that does not align with the stated purpose of saving and managing scoring parameter versions. Scope drift is dangerous because operators may grant this skill broader trust than warranted, while it quietly processes external market data and derived analytics.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The hardcoded external endpoint and browser-mimicking request headers establish outbound network access to futunn.com without any apparent justification from the skill's declared role. In an agent environment, undeclared network access is dangerous because it can transmit metadata externally and consume untrusted third-party data under the guise of a local parameter manager.

Static analysis

No suspicious patterns detected.