Back to skill

Security audit

Quant Tools 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a quantitative finance research skill with expected market-data and backtesting capabilities, but users should treat its trading-related workflows carefully.

Install only if you intend to use quantitative finance tooling. Before using live trading, deployment, or external-data workflows, confirm the exact action, credentials, account scope, and whether the result is research-only, paper trading, or production/live trading.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad terms such as “量化”, “quant”, “因子”, and “学术研究”, which can cause the skill to activate for loosely related user requests. In a skill that discusses trading, backtesting, data interfaces, and API/service packaging, overbroad invocation increases the chance of unintended exposure to impactful financial workflows or external-data actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes capabilities involving real trading frameworks, external financial data retrieval, API wrapping, and multi-user research environments, but does not clearly warn users about external network access, operational risk, or the consequences of trading-related actions. In this context, omission of warnings is more dangerous because users may assume these tools are purely analytical when they can support live trading, data ingestion, and deployment workflows.

Static analysis

No suspicious patterns detected.