Back to skill

Security audit

Interbank Funding Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed China interbank funding workflow assistant with local templates and a collateral-check script, not a hidden trading or data-exfiltration tool.

Install only if you want a China CNY interbank funding and pledged-repo assistant. Treat its outputs as decision support, not trade authorization; verify real prices, account rules, collateral eligibility, limits, and settlement steps with your institution's approved systems and staff. Do not put unsanitized account, counterparty, token, or confidential position data into shared templates.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill explicitly instructs the agent to load references, templates, and a verification script, which implies file-read capability without a corresponding declared permission boundary. That creates a mismatch between what the skill can cause the agent to access and what reviewers or policy systems may expect, increasing the risk of unintended local file exposure or use of sensitive repository content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation text is extremely broad, covering many common role-play and trading-related requests, so the skill may trigger in situations the user did not intend. In a financial workflow skill, over-broad auto-activation is risky because it can steer outputs toward specialized trading procedures, collateral checks, or data-handling behaviors without clear user opt-in.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill content mandates a Chinese-language workflow and domain framing without offering a language or locale choice. While not directly a code-execution issue, this can cause user misunderstanding, incorrect interpretation of financial constraints, or silent misuse if a non-Chinese-speaking user receives specialized output they cannot properly review.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation without any narrow activation constraints, so the agent may auto-trigger this trader workflow on loosely related prompts. Because this skill is designed to steer financial analysis and trading-style decision-making, ambiguous activation increases the chance of inappropriate role takeover, unintended financial guidance, or misuse in contexts where the user did not explicitly request this specialized behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are very broad, including common requests like '帮我验券' or '这些券能不能押', which can cause the skill to activate in loosely related conversations without clear user intent or context confirmation. In this skill, unintended activation is more sensitive because it can produce operationally significant collateral-eligibility judgments that users may rely on in funding or repo workflows.

Static analysis

No suspicious patterns detected.