Back to skill

Security audit

financial-report-analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill performs local financial-report extraction, charting, and report generation without evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable processing financial documents locally and keeping generated extracted text, JSON, charts, and reports on disk. Treat the analysis as a rough aid, verify extracted figures manually, and do not rely on it as investment advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The implemented script is a generic PDF text/table extraction utility. Its behavior is limited to reading a local PDF file, extracting raw text and tables page by page, and writing the extracted data to output files. While PDF extraction could be a supporting component of a financial analysis skill, the declared purpose claims substantially more advanced domain-specific capabilities—financial metric extraction, analytical interpretation, charting, and investment report generation—which are not present in this code chunk. Therefore, the code materially underdelivers relative to the declared description, making it a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is limited to visualization of pre-existing structured financial data. It reads a JSON file, creates chart images with matplotlib, and writes them to a local output directory. This partially aligns with the declared chart-generation aspect, but materially falls short of the broader declared purpose of intelligent PDF financial report parsing, automatic data extraction, and investment report generation. There is no evidence of PDF handling, OCR/text extraction, report analysis logic, comparison across reporting periods, or narrative investment recommendations in this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises an end-to-end PDF financial report analysis skill: ingesting PDF reports, extracting key data, generating charts, and producing an investment reference report. However, this code chunk implements only the report-generation portion of that workflow. It expects pre-parsed financial data in a JSON file, formats sections such as summary, profitability, solvency, operations, risk, and conclusion, and saves a markdown report. There is no PDF handling, OCR/text extraction, table extraction, charting/visualization library usage, or cross-period comparison logic in the supplied code. Therefore, the code's actual behavior is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broader end-to-end financial report analysis workflow: parsing PDF financial reports, extracting metrics, generating visual analytics, and producing investment reference reports across Chinese A-shares, Hong Kong, and US equities. The supplied code chunk is a narrower text parser. It expects input from a .txt file or JSON containing pre-extracted full_text, then applies regex-based extraction for company name, stock code, report period, and selected financial metrics. It saves the extracted structured data to JSON and prints a console summary. There is no PDF ingestion, no visualization logic, no report-writing or investment recommendation logic, and no comparison across reporting periods. Also, the stock code extraction appears tailored mainly to mainland Chinese 6-digit formats rather than Hong Kong or US tickers. Therefore the actual behavior materially underdelivers relative to the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases are very broad conversational requests such as asking to analyze a PDF financial report or compare two companies' financial status. In a skill-routing environment, overly generic triggers can cause unintended activation on normal user queries, leading to unnecessary access to local files or financial documents and misrouting the user into an investment-analysis workflow they did not explicitly request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README asserts 'local processing' and 'no cloud upload' as a security/privacy guarantee, but this file provides no evidence or technical controls to substantiate that claim. For a skill handling potentially sensitive financial documents, an inaccurate privacy assurance can mislead users into exposing confidential data under false assumptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs the agent to read user-supplied PDFs and generate outputs such as charts and reports, but it does not declare any explicit tool scope or permissions. That creates an authorization ambiguity where the runtime may grant broader file read/write access than users or platform policy expect, increasing the risk of unintended filesystem access or file creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation language is broad enough that normal conversation about analyzing a report could trigger the skill without strong user intent confirmation. In an agent environment with file and write capabilities, over-broad activation can cause unintended processing of uploaded documents and creation of derived outputs when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Examples like '帮我分析这份财报' are very generic and can overlap with common requests, making accidental activation more likely. In contexts where the skill reads files and writes reports or charts, accidental invocation expands the chance of processing sensitive documents unnecessarily or performing actions outside the user's precise expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire template is written as a fixed Chinese-only report format, including headings, labels, and disclaimer text, with no indication that users may choose another language or that the template is restricted to a specific Chinese-speaking compliance context. This can violate language/locale policy requirements that prohibit forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language text that forces a specific language for the skill's title, description, usage, and runtime output. Under the policy, language constraints should offer user choice or be explicitly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a financial-report analyzer that automatically extracts key financial indicators, generates visual charts, and produces investment reference reports. This file implements only low-level PDF text and table extraction plus JSON/TXT file output, with no financial parsing, comparison logic, charting, or report generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language descriptions and generated report content are written entirely in Chinese, indicating the skill is designed to operate in a fixed language. Under the policy, a forced language or locale without user opt-in should be flagged unless the regional constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire changelog is written in Chinese, including the title and all feature descriptions, with no indication that the skill is region-specific or that other language options are available. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

SQP-3 适用于所有文件。文档整体仅提供中文标题与中文使用场景,并在支持格式中写明“中文财报优化”,但未说明是否支持其他语言或允许用户选择输出语言,可能构成语言/locale 约束未显式 opt-in 的问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is entirely in Chinese, including the usage instructions and disclaimer, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill effectively requires a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and all instructional content are presented exclusively in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This matches the language/locale policy concern for natural-language content that imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions and CLI output exclusively in Chinese, including the module docstring and user-facing prompts. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern unless the skill is clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring for parse_from_file states that the input path supports only .txt or .json. However, the implementation accepts any existing file whose suffix is not .json and reads it as UTF-8 text, which directly contradicts the documented contract.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module and function documentation describe this tool as extracting and parsing financial data from text, which implies read/compute behavior. In the CLI path, the code additionally persists results to a new local file, a side effect not reflected in the description of the tool or parser entrypoint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.