Back to skill

Security audit

InvestToday Finance Data

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent financial-data skill, but its credential setup instructions and contaminated finance examples need review before installation.

Install only if you trust the InvestToday CLI package and understand where it stores your API key. Prefer interactive or environment-based secret entry over putting keys directly in shell commands, avoid --skip-verify unless you understand the consequence, and treat outputs as research data rather than financial advice. Be aware that some included reference examples appear inconsistent or contaminated, so important financial conclusions should be verified against authoritative sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (59)

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
The example output includes a detailed banking-style customer narrative with VIP status, industry, revenue, credit history, and loan amounts, which appears unrelated to the endpoint and plausibly sensitive. Because this is embedded in reference documentation, it risks unauthorized disclosure, reuse in prompts or exports, and normalization of exposing confidential financial relationship data.

Hidden Instructions

High
Category
Prompt Injection
Content
| `dmaDma` | DMA指标 | `3.75` |
| `dmaAma` | 平行线差指标 | `-0.015` |
| `mtmMtm` | MTM动量线 | `0` |
| `trixTrix` | 三重指数平滑平均线​  | `0` |
| `trixTrma` | 三重指数平滑平均线的移动平均线 | `0.015` |
| `pageNum` | page number | `1` |
| `pageSize` | page size | `100` |
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
| `dmaDma` | DMA指标 | `3.75` |
| `dmaAma` | 平行线差指标 | `-0.015` |
| `mtmMtm` | MTM动量线 | `0` |
| `trixTrix` | 三重指数平滑平均线​  | `0` |
| `trixTrma` | 三重指数平滑平均线的移动平均线 | `0.015` |
| `pageNum` | page number | `1` |
| `pageSize` | page size | `100` |
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
| `dmaDma` | DMA指标 | `3.75` |
| `dmaAma` | 平行线差指标 | `-0.015` |
| `mtmMtm` | MTM动量线 | `0` |
| `trixTrix` | 三重指数平滑平均线​  | `0` |
| `trixTrma` | 三重指数平滑平均线的移动平均线 | `0.015` |
| `pageNum` | page number | `1` |
| `pageSize` | page size | `100` |
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
| `dmaDma` | DMA指标 | `3.75` |
| `dmaAma` | 平行线差指标 | `-0.015` |
| `mtmMtm` | MTM动量线 | `0` |
| `trixTrix` | 三重指数平滑平均线​  | `0` |
| `trixTrma` | 三重指数平滑平均线的移动平均线 | `0.015` |
| `pageNum` | page number | `1` |
| `pageSize` | page size | `100` |
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The title, description, examples, and operational guidance are presented in Chinese throughout the file. Under the policy, forcing a specific language without an explicit user choice or documented justification is a natural-language policy violation.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly instructs use of a non-interactive initialization command that accepts an API key on the command line and may create or update local configuration files, but it does not warn about secret exposure risks. Command-line secrets can be captured in shell history, process listings, logs, or persisted in insecure local config, which is especially risky in agent or shared execution environments.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
Line L004 states that the reference documents are maintained in Chinese, and the rest of the index links predominantly to Chinese-titled documents despite this being an `.en.md` file. This imposes a specific language on users without opt-in or an alternative, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file presents all user-facing guidance and navigation labels exclusively in Chinese, starting from the title and continuing throughout the index. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents an API that sends arbitrary user-provided natural-language text to an entity-recognition endpoint, but it gives no warning about privacy, retention, logging, or restrictions on submitting sensitive data. In an agent setting, users may include personal, confidential, or non-public financial information in free text, which can then be transmitted to a backend service without informed consent or minimization controls.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documented output for the fund redemption-status endpoint includes examples and labels that appear unrelated to fund operations, such as '客户订单管理系统' and a release-planning style remark about a Q2/Q3 feature launch. This kind of schema/example divergence can mislead downstream agents or users into misclassifying data, trusting incorrect fields, or propagating non-financial content into financial workflows, which is especially risky in a finance data skill where accuracy and field semantics matter.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
This documentation exposes multiple personal profile fields such as name, gender, birth date, education, school, and employment status without any handling guidance, minimization note, or privacy warning. In the context of a financial research skill, these fields can enable unnecessary collection, retention, or misuse of personally sensitive information about identifiable individuals.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documented example for `backgroundDesc` contains a banking customer and loan narrative that is unrelated to fund manager information and appears to disclose sensitive financial/business details. In a finance-data skill, this suggests sample data contamination or accidental inclusion of real-world sensitive content, which can propagate into downstream use, testing, or model outputs.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The '货币市场质押式回购指标' section describes the endpoint as a government bond yield curve query, but the actual returned fields are repo-market metrics such as open/close rates, weighted average rates, tenor, and volume. This kind of semantic mismatch can mislead downstream agents or users into calling the wrong tool or misinterpreting output, producing incorrect macro/interest-rate analysis and potentially unsafe financial conclusions.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The '上市公司的诉讼仲裁' section contains example output values and field descriptions that are plainly unrelated to litigation data, such as bank counter deposit handling, project acceptance progress, and shipping remarks. In a finance research skill, this kind of schema contamination can mislead downstream agents or users into treating fabricated or cross-domain fields as authoritative legal-risk data, producing incorrect compliance, credit, or investment assessments.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documentation repeatedly frames the endpoints as suitable for '投资决策' and '投研场景' while providing no clear disclaimer that outputs are informational data only and not personalized investment advice. In a finance-focused skill, this increases the risk that downstream agents present model-generated interpretations or rankings as actionable recommendations, creating compliance, user-harm, and suitability risks.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This documentation exposes multiple endpoints that generate company fundamentals, prospects, investment themes, and explicit risk conclusions framed as decision support, but it does not include a clear disclaimer that outputs are informational and not personalized investment advice. In a finance-focused skill, that omission can cause downstream agents or users to over-trust model-generated summaries as actionable recommendations, increasing regulatory, suitability, and user-harm risk.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
前文将 `stock/str-trend-ind` 声明为 `GET` 接口,而后文同一路径 `stock/str-trend-ind` 又声明为 `POST`,且 tool_id 不同。这会导致调用方无法准确判断接口真实行为,属于文档对接口意图的直接冲突。

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The markdown explicitly frames the data as useful for 'investment decision-making' without any warning that outputs are informational only and not financial advice. In a finance skill, that increases the risk that users or downstream agents over-rely on technical indicators for consequential financial actions, potentially causing harmful or noncompliant behavior.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
此处将 `stock/str-trend-ind` 定义为 `POST`,与前面同一路径的 `GET` 定义不一致,形成双向矛盾。对于代理技能而言,这种不一致会直接影响工具选择和参数封装方式。

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation for the profitability endpoint states it returns '单季度' metrics, but the endpoint name, title, and surrounding file clearly indicate TTM data. In a finance-data skill, this semantic mismatch can cause downstream models, analysts, or automated workflows to interpret trailing-twelve-month metrics as quarterly performance, leading to materially incorrect comparisons, trend analysis, or investment research outputs.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
This markdown file presents all operational instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Missing User Warnings

Low
Confidence
85% confidence
Finding
This markdown file includes executable API invocation examples that send request body data to a remote endpoint, but the description does not include any user-facing warning about network transmission or data handling. Under the markdown-specific warning criterion, externally transmitted query content should be disclosed when the skill behavior affects privacy or data handling.

Intent-Code Divergence

Low
Confidence
95% confidence
Finding
L023-L024 明确说明 `fundCode` 与 `fundCodes` 是二选一且必须提供其一,但 L045 的注释写成“可选参数”,会让使用者误以为两者都可省略。这属于文档注释与前文接口约束直接矛盾,而非单纯信息不完整。

Missing User Warnings

Low
Confidence
85% confidence
Finding
The example shows another POST request with user-supplied parameters, yet the surrounding documentation does not warn users that their inputs are transmitted to a backend service. This is a markdown-level omission related to privacy and system interaction transparency rather than a code-level flaw.

Static analysis

No suspicious patterns detected.