Back to skill

Security audit

Jukan Investment Strategy/Jukan投资策略

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed finance-analysis writing aid that imitates a public analyst’s methodology and style, with no evidence of hidden data access or harmful automation.

Use this as an AI-generated analysis framework, not as Jukan05’s own work or endorsed advice. Be especially careful if sharing outputs publicly: label them as AI-generated, verify all financial data independently, and do not rely on the report as investment advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The instruction to generate analysis 'as if written by Jukan05 himself' creates an impersonation-style behavior that can mislead users into believing the output is authored, endorsed, or directly representative of a real person. In a financial-analysis context, that raises deception, reputational, and reliance risks, especially when paired with historical-view loading and stylistic mimicry.

Static analysis

No suspicious patterns detected.