Back to skill

Security audit

Stock Analyzer | 股票深度分析

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is coherent and disclosed, with expected web data lookup but no hidden persistence, credential access, or destructive behavior.

Before installing, understand that the skill may contact third-party financial sites using stock tickers or company names you provide, and its investment conclusions should be treated as research assistance, not professional financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match ordinary investing conversations, which can cause the skill to activate in situations the user did not clearly intend. In a skill that may perform detailed analysis and invoke external data-gathering tools, ambiguous activation increases the risk of unexpected tool use, misleading outputs, or overreach into regulated financial-advice-like behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to use exec+curl, web_fetch, and browser access to third-party financial sites, but it does not clearly disclose outbound network activity or obtain user confirmation. This can lead to unexpected transmission of user-provided stock interests or query contents to external services and creates unnecessary exposure to untrusted remote content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.