Back to skill

Security audit

Taiwan Fund

Security checks for vulnerabilities and agentic risk

Overview

This skill is a public Taiwan fund lookup CLI with disclosed network data sources and only limited cache writing.

Install only if you are comfortable with a CLI that queries third-party public finance endpoints and stores a local TDCC cache. Treat the holdings claim as incomplete: this skill mainly provides NAV, performance, benchmark comparison, exchange rates, watchlist output, and links or Tavily prompts for further detail.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description does not match the documented behavior: additional third-party data sources are used, one advertised source is not used, and a claimed feature (holdings retrieval) is not substantiated. This is dangerous because trust and review decisions are made from the manifest/description; hidden or misstated network dependencies increase supply-chain, privacy, and compliance risk and can mislead users about what data is fetched and from where.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network access and cache/file-writing behavior in its documented commands and data-flow, but does not declare any explicit tool scope or permissions. This weakens policy enforcement and user awareness because a host agent may permit broader-than-expected outbound requests and local writes without an auditable least-privilege boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and implemented commands cover NAV lookup, comparison, watchlist, search, exchange rates, and URL generation, but there is no code that actually fetches or returns fund holdings. Instead, the tool tells the user to use external tavily extraction for detailed holdings at L383-L385 and L514, which does not fulfill the manifest's stated 'holdings' capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code file contains natural-language usage text and command descriptions in Chinese, and the rest of the user-facing messages throughout the script are also fixed to that locale. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy violation when no alternative or opt-in is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stated description limits data sourcing to cnyes/MoneyDJ, but this file fetches exchange rates from open.er-api.com, offshore fund data from TDCC, and benchmark performance from Yahoo Finance. Those extra data providers materially expand actual behavior beyond the manifest's described source scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.