Back to skill

Security audit

ATopChaser

Security checks for vulnerabilities and agentic risk

Overview

This skill runs a local script to fetch public A-share market movers and asks the agent to summarize them with financial-risk disclaimers.

Before installing, understand that this skill launches a headless browser and contacts a third-party Chinese market-data site to retrieve public stock rankings. Treat its buy/hold judgments as general automated commentary, not financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill metadata says it fetches A-share Top 10 gainers and analyzes whether they are worth buying, but the instructions only mandate running a local script and repeating its output, while the underlying behavior reportedly includes web automation/scraping of a third-party site that is not disclosed. Hidden network access and undisclosed data collection paths reduce auditability, can bypass user expectations or policy controls, and may expose the agent environment to unreviewed external content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill specification is written as mandatory Chinese-language operating instructions and provides no option to adapt to the user's preferred language or locale. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill should both obtain the current A-share Top 10 gainers and provide analysis on whether they are worth buying. In this file, the code only launches a browser, scrapes the ranking table, builds a DataFrame, and prints the results; there is no analysis logic, scoring, recommendation, or buy decision output.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/list_top10.py (reported line 17)May include surrounding context.

python
# ====================== 1. 抓取当天涨幅Top10(增强额外信息) ======================
        print("正在从同花顺抓取当天A股涨幅Top10...")
        await page.goto("https://data.10jqka.com.cn/market/zdfph/", timeout=60000)
        await page.wait_for_timeout(6000)  # 等待表格完全加载

        top10 = []

Static analysis

No suspicious patterns detected.