Back to skill

Security audit

财经情报局

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language finance news summarizer that writes local reports, but the included fetcher is mostly a scaffold and does not show hidden or destructive behavior.

Install only if you want a Chinese-language finance briefing helper. Expect local files under finance-news by default, review any investment conclusions manually, and note that the included fetch logic appears incomplete despite listing many sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs creation of a local finance-news/ directory and references scripts that generate cached data and reports, which implies file-write capability, but it does not declare any explicit tool scope or permissions boundary. This can lead to overbroad execution in hosts that rely on manifest-declared capabilities, increasing the risk of unintended filesystem writes or abuse if the script behavior changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing description is entirely in Chinese and presents the skill as operating in that language, but the file does not state that this is optional or limited to a Chinese-language audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to activate on common terms like '财经新闻', '股市', '市场动态', or any stock/industry name, which may cause the skill to run in conversations where the user did not explicitly request news aggregation or external fetching. In a network-enabled skill, over-triggering can cause unnecessary data access, unintended script execution, or irrelevant financial guidance in ambiguous contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level documentation presents the script as an operational multi-source news fetcher. In contrast, the concrete source functions shown here do not fetch anything and simply return empty results, and the comments explicitly say the real implementation still needs browser-tool calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file's natural-language descriptions and user-facing behavior are explicitly Chinese-only (for example, the module description and CLI help text are all in Chinese), with no indication that users can opt into another language. Under the locale policy rule, forcing a specific language without user choice is a policy concern unless clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill reference is written only in Chinese, including headings, rules, and validation instructions, with no indication that users may choose another language or locale. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains only Chinese headings and instructions, which can amount to a language-policy constraint if users are not given a language or locale choice. The policy allows locale constraints when clearly documented and justified, but this file provides no such justification or opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a finance intelligence skill focused on aggregating news, analyzing signals, and generating investment references. While report generation is aligned, this file also performs filesystem persistence by creating dated cache and report directories and writing JSON/Markdown files, which is broader than a pure fetch/analyze operation implied by this script's own description as a '抓取核心脚本'.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command-line interface and help text imply users can fetch from the listed configured sources such as eastmoney and others. However, fetch_news only dispatches cls and wallstreet, while all other sources fall through to an empty result, creating a direct mismatch between user-facing intent and actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.