Back to skill

Security audit

News Alert | 新闻监控

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent portfolio-news alert helper, but it asks for ongoing monitoring and push alerts around sensitive holdings without enough user control or data-handling detail.

Review this skill carefully before installing. It may be useful if you want Chinese-language portfolio news alerts, but you should only use it where you are comfortable sharing or exposing holdings information and should look for explicit controls for opt-in monitoring, stopping alerts, and deleting any stored portfolio data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises real-time monitoring of companies in the user’s holdings and immediate message pushes, but it does not explain what portfolio data is collected, how it is stored, which sources are queried, or how alerts are delivered. Because holdings information is financially sensitive, missing privacy and data-handling constraints raises risk of unauthorized collection, retention, or disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases like “最近有什么新闻” and “XXX 有什么新消息” are broad natural-language expressions that can easily appear in ordinary conversation, increasing the chance the skill activates when the user did not specifically intend to invoke portfolio news monitoring. In a finance-related skill, unintended activation can expose or infer sensitive investment interests and cause confusing or unsolicited responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The proactive condition “发现重大新闻时主动提醒” is underspecified and does not define user consent, scope, timing, or confidence thresholds for push behavior. That ambiguity can lead to unsolicited notifications, excessive surveillance-like behavior, or actions based on inaccurate classification of “major” events.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description, trigger phrases, commands, and output examples are all specified in Chinese, with no indication that users may opt into another language. This can violate language/locale policy when a skill implicitly mandates one language without user choice or clear region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.