Back to skill

Security audit

虾皮个股分析报告

Security checks for vulnerabilities and agentic risk

Overview

This is a finance-report writing skill that uses current public sources and a verification subagent, with no evidence of hidden installation, persistence, credential theft, or destructive behavior.

Install this if you want a structured A-share company research-report workflow that uses live searches, data tools, links, and an internal verification pass. Avoid giving it confidential notes you do not want included in a generated article or reviewed by a subagent, and independently verify outputs before making financial decisions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
Overly broad trigger phrases such as generic requests for stock analysis can cause the skill to activate in contexts the user did not intend, increasing the chance of unintended workflow execution. In this skill, accidental invocation is more concerning because the workflow strongly pushes external searches, subagent use, and link-heavy processing, which can lead to unnecessary external data access or disclosure of user-provided content.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill mandates sending the full generated article to an independent subagent and instructs that subagent to access external links for validation, but it does not require explicit user consent or disclose the external-access/data-transfer implications. This creates a real data-handling risk: user-supplied content, embedded links, and possibly sensitive prompts or proprietary notes could be forwarded to another agent or external destinations without clear authorization.

Static analysis

No suspicious patterns detected.