Back to skill

Security audit

虾皮股市罗盘

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent A-share market analysis skill with normal finance-risk and external-data-provider cautions, not evidence of hidden or malicious behavior.

Before installing, confirm you trust the daxiapi CLI/provider and consider pinning a known package version instead of relying on `latest`. Treat any daxiapi token as a secret, and treat generated market reports as informational analysis rather than a sole basis for investment decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises broad trigger phrases such as '市场综合分析' and '仓位判断', which are generic enough to match ordinary financial conversations and cause unintended invocation. Because this skill produces market/positioning guidance, accidental activation can inject unsolicited financial advice into unrelated contexts, increasing the risk of misleading or inappropriate recommendations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly answers whether users should hold stocks and how much position to take, yet it does not present a clear financial-risk disclaimer or state that outputs are informational only. In the financial context, this omission makes the skill more dangerous because users may reasonably treat the output as actionable investment advice, potentially leading to harmful real-world losses.

Static analysis

No suspicious patterns detected.