Back to skill

Security audit

段永平投资判断 · 价值投资方法论

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese markdown-only investing framework skill with clear financial disclaimers and no code, network access, persistence, or hidden authority.

Install only if you want a Chinese-language educational value-investing framework. Do not rely on its output as the sole basis for real-money decisions; verify current financial data and consider qualified professional advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

Although the README says the skill is not investment advice, it prominently describes helping users decide whether an investment is worth making and applying a decision framework to specific stocks. For a markdown skill description, this can affect user finances, and the warning does not explicitly advise users to verify independently or avoid relying on the output for real-money decisions beyond a brief disclaimer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples are broad enough to activate on generic investment-decision questions, which can cause the skill to engage in high-stakes financial contexts beyond a narrowly scoped educational framework. In a financial skill, overbroad triggering increases the chance that users receive quasi-advisory guidance when they may only be discussing investments generally, creating compliance, safety, and user-harm risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation conditions are broad enough to trigger on general investment, business, and decision-making conversations, which can cause the skill to engage outside a clearly bounded use case. In a financial domain, over-broad routing is risky because users may receive quasi-investment guidance in ambiguous contexts where the system has not established suitability, jurisdictional constraints, or whether the user is seeking regulated advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill presents all instructions, triggers, and decision templates exclusively in Chinese, which effectively forces a specific language experience. The file does not offer multilingual support, user opt-in, or any explanation that the skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The entire skill description is written in Chinese and presents the skill as operating in that language, with no indication that users may choose another language or locale. Under the language/locale policy, a forced language without opt-in can be a natural-language policy concern unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.