Back to skill

Security audit

fund-analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a fund-data helper, but its documentation and implementation disagree about data sources and it mentions cookie-based access without adequate safety guidance.

Install only if you are comfortable with a China-market fund helper that actually uses Eastmoney/Tiantian Fund data despite Alipay wording. Do not paste, hardcode, log, or share Alipay cookies or other session data when using or extending it, and verify financial results against trusted sources before making investment decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims comprehensive fund query and analysis features from Alipay, but the code behavior reportedly only extracts some interval returns from Eastmoney and lacks the broader promised functions. In a financial-analysis skill, this discrepancy increases risk of user deception, poor governance, and bad downstream decisions from incomplete or mislabeled data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims comprehensive fund query and analysis features from Alipay, but the code behavior reportedly only extracts some interval returns from Eastmoney and lacks the broader promised functions. In a financial-analysis skill, this discrepancy increases risk of user deception, poor governance, and bad downstream decisions from incomplete or mislabeled data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims comprehensive fund query and analysis features from Alipay, but the code behavior reportedly only extracts some interval returns from Eastmoney and lacks the broader promised functions. In a financial-analysis skill, this discrepancy increases risk of user deception, poor governance, and bad downstream decisions from incomplete or mislabeled data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims comprehensive fund query and analysis features from Alipay, but the code behavior reportedly only extracts some interval returns from Eastmoney and lacks the broader promised functions. In a financial-analysis skill, this discrepancy increases risk of user deception, poor governance, and bad downstream decisions from incomplete or mislabeled data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims comprehensive fund query and analysis features from Alipay, but the code behavior reportedly only extracts some interval returns from Eastmoney and lacks the broader promised functions. In a financial-analysis skill, this discrepancy increases risk of user deception, poor governance, and bad downstream decisions from incomplete or mislabeled data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and instructs use of shell commands and network-backed scripts, but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and review gap: an agent may invoke shell/network capabilities without explicit least-privilege boundaries, making misuse or unsafe execution harder to govern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and core usage instructions are written in Chinese and present the skill as operating in that language without any stated user opt-in or alternative locale. This can violate language/locale policy when a skill implicitly forces a specific language rather than offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide explicitly recommends simulating a logged-in session and using cookies to access fund data, but it does not warn about credential handling, session theft, privacy leakage, or site terms/compliance risks. In a skill that may be used by non-expert operators, this can lead users to paste personal authentication cookies into scripts or logs, exposing account data or enabling account hijacking if those cookies are mishandled.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata says the data source is Alipay fund pages, but this script actually fetches live data from Eastmoney. That mismatch can mislead users, reviewers, and downstream systems about trust boundaries, licensing, privacy expectations, and operational dependencies. In a finance-related skill, undisclosed third-party data sourcing is materially risky because analysis quality and provenance matter.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring explicitly states the data source is 天天基金网, contradicting the manifest's claim that data comes from Alipay. Conflicting provenance statements are dangerous because they obscure what external service is actually queried, undermining user consent, auditability, and compliance expectations for financial-data tooling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script fetches fund ranking data from Eastmoney while the skill metadata says the data source is Alipay. This is a supply-chain/integrity issue because users and downstream systems may trust the skill under false assumptions about provenance, coverage, permissions, or compliance, which can lead to incorrect decisions or policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script presents all user-facing messages and usage instructions in Chinese, which imposes a specific language on users without any visible opt-in or alternative. The policy explicitly calls for flagging language or locale constraints when the skill does not offer user choice or clearly justify the restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

代码将“近1周”对应到 sy_1y 字段,而同一映射中“近1年”也对应 sy_1y。这意味着输出声称展示的是1周收益率,但实际提取的是1年收益率,属于代码中标签意图与实际行为的直接矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language instructions and output text that force a specific language/locale for all users. The policy for this category says to flag language or locale constraints unless the skill offers user opt-in or clearly documents a justified regional limitation, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes the skill as sourcing fund data from 支付宝基金页面, but this script's module docstring and request target show it retrieves holdings data from 天天基金网 / Eastmoney instead. That is a direct description-to-behavior mismatch about where the skill's information originates, which can materially affect user expectations about provenance and coverage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata says fund data comes from Alipay pages, but this script actually requests data from Eastmoney. This is a supply-chain and trust-boundary issue: users and platform reviewers may make consent, compliance, or reliability decisions based on the declared source, while the code silently sends requests to a different third party. In a finance-related skill, undeclared external data sources are more sensitive because they affect transparency, legal/compliance expectations, and data provenance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill guide is entirely written in Chinese and does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-speaking/regional context. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language descriptions and user-facing strings exclusively in Chinese, including the module docstring and CLI help/output. Under the stated policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language descriptions and user-facing messages exclusively in Chinese, and the CLI does not provide any language or locale opt-in. Under the policy, forcing a specific language without user choice can be a locale-policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring states the script purpose entirely in Chinese, and the rest of the user-facing messages in the file also appear to assume Chinese output. For an all-file-types language policy check, this is a locale/language constraint presented without user opt-in or justification that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTTP header sets Accept-Language to prefer zh-CN, and the script’s user-facing text and documentation are entirely in Chinese. This imposes a specific language/locale choice rather than offering the user a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.