Back to skill

Security audit

finance-theory-master

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language finance theory reference skill with local lookup and validation helpers, not a hidden or high-impact automation package.

Install this as a finance theory reference skill, not as an investment advisor. Use the bundled Python helpers only when you want local search, validation, or regeneration of the included datasets, and remember that the content is primarily Chinese-language and may need translation for other users.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose presents the skill as a finance theory and history knowledge framework, but the content also includes operational code behaviors such as filesystem access, CSV generation, validation, and shell execution. This mismatch is dangerous because reviewers and users may trust it as a passive reference skill while it retains active local execution and mutation capabilities that could be abused or could unexpectedly alter data.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · data/financial_history_timeline.csv (reported line 1)May include surrounding context.

text
theory_id,name_cn,abbrev,proposer,year,module,core_claim,core_assumption,applicable_scene,main_limitation,hypothesis_strength,evidence_status,evidence_note,complementary,conflicting,key_reference
pv_dcf,现值与现金流贴现框架,DCF,传统框架,—,资产定价,资产价格等于其未来全部支付的现值之和,现金流可预测;贴现率可估计且期间稳定,现金流可预测的成熟资产估值;企业估值,终值假设主导结果;对贴现率极敏感;不是可证伪的理论而是恒等式,框架级,稳健,作为恒等式稳健;作为可证伪的理论不存在,全部资产定价模型|公司金融,—,教科书标准框架
sdf,随机贴现因子框架,SDF,Cochrane 系统化,2001,资产定价,所有资产定价理论都是对随机贴现因子 m 的不同指定,p = E(mx),无(组织性框架,本身不含假设),统一理解与比较各类资产定价模型;组织讨论,不指定 m 的具体形式就无法进行计算,框架级,稳健,,CAPM|CCAPM|多因子模型,—,"Cochrane (2001), Asset Pricing, Princeton University Press"
capm,资本资产定价模型,CAPM,Sharpe、Lintner、Mossin,1964,资产定价,只有系统性风险被定价,E(Ri) = Rf + βi[E(Rm) − Rf],均值方差偏好;同质预期;无摩擦市场;可按同一无风险利率无限借贷;单期,资本成本估算;绩效归因;风险分解;作为基准参照,Roll 批判使市场组合不可观测、严格不可检验;横截面实证表现差,强,有争议,,投资组合理论|公司金融(WACC),多因子模型|行为金融,"Sharpe (1964), JF"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · data/investor_cases.csv (reported line 1)May include surrounding context.

text
theory_id,name_cn,abbrev,proposer,year,module,core_claim,core_assumption,applicable_scene,main_limitation,hypothesis_strength,evidence_status,evidence_note,complementary,conflicting,key_reference
pv_dcf,现值与现金流贴现框架,DCF,传统框架,—,资产定价,资产价格等于其未来全部支付的现值之和,现金流可预测;贴现率可估计且期间稳定,现金流可预测的成熟资产估值;企业估值,终值假设主导结果;对贴现率极敏感;不是可证伪的理论而是恒等式,框架级,稳健,作为恒等式稳健;作为可证伪的理论不存在,全部资产定价模型|公司金融,—,教科书标准框架
sdf,随机贴现因子框架,SDF,Cochrane 系统化,2001,资产定价,所有资产定价理论都是对随机贴现因子 m 的不同指定,p = E(mx),无(组织性框架,本身不含假设),统一理解与比较各类资产定价模型;组织讨论,不指定 m 的具体形式就无法进行计算,框架级,稳健,,CAPM|CCAPM|多因子模型,—,"Cochrane (2001), Asset Pricing, Princeton University Press"
capm,资本资产定价模型,CAPM,Sharpe、Lintner、Mossin,1964,资产定价,只有系统性风险被定价,E(Ri) = Rf + βi[E(Rm) − Rf],均值方差偏好;同质预期;无摩擦市场;可按同一无风险利率无限借贷;单期,资本成本估算;绩效归因;风险分解;作为基准参照,Roll 批判使市场组合不可观测、严格不可检验;横截面实证表现差,强,有争议,,投资组合理论|公司金融(WACC),多因子模型|行为金融,"Sharpe (1964), JF"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · data/policy_toolkit.csv (reported line 1)May include surrounding context.

text
theory_id,name_cn,abbrev,proposer,year,module,core_claim,core_assumption,applicable_scene,main_limitation,hypothesis_strength,evidence_status,evidence_note,complementary,conflicting,key_reference
pv_dcf,现值与现金流贴现框架,DCF,传统框架,—,资产定价,资产价格等于其未来全部支付的现值之和,现金流可预测;贴现率可估计且期间稳定,现金流可预测的成熟资产估值;企业估值,终值假设主导结果;对贴现率极敏感;不是可证伪的理论而是恒等式,框架级,稳健,作为恒等式稳健;作为可证伪的理论不存在,全部资产定价模型|公司金融,—,教科书标准框架
sdf,随机贴现因子框架,SDF,Cochrane 系统化,2001,资产定价,所有资产定价理论都是对随机贴现因子 m 的不同指定,p = E(mx),无(组织性框架,本身不含假设),统一理解与比较各类资产定价模型;组织讨论,不指定 m 的具体形式就无法进行计算,框架级,稳健,,CAPM|CCAPM|多因子模型,—,"Cochrane (2001), Asset Pricing, Princeton University Press"
capm,资本资产定价模型,CAPM,Sharpe、Lintner、Mossin,1964,资产定价,只有系统性风险被定价,E(Ri) = Rf + βi[E(Rm) − Rf],均值方差偏好;同质预期;无摩擦市场;可按同一无风险利率无限借贷;单期,资本成本估算;绩效归因;风险分解;作为基准参照,Roll 批判使市场组合不可观测、严格不可检验;横截面实证表现差,强,有争议,,投资组合理论|公司金融(WACC),多因子模型|行为金融,"Sharpe (1964), JF"

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · data/theory_index.csv (reported line 1)May include surrounding context.

text
theory_id,name_cn,abbrev,proposer,year,module,core_claim,core_assumption,applicable_scene,main_limitation,hypothesis_strength,evidence_status,evidence_note,complementary,conflicting,key_reference
pv_dcf,现值与现金流贴现框架,DCF,传统框架,—,资产定价,资产价格等于其未来全部支付的现值之和,现金流可预测;贴现率可估计且期间稳定,现金流可预测的成熟资产估值;企业估值,终值假设主导结果;对贴现率极敏感;不是可证伪的理论而是恒等式,框架级,稳健,作为恒等式稳健;作为可证伪的理论不存在,全部资产定价模型|公司金融,—,教科书标准框架
sdf,随机贴现因子框架,SDF,Cochrane 系统化,2001,资产定价,所有资产定价理论都是对随机贴现因子 m 的不同指定,p = E(mx),无(组织性框架,本身不含假设),统一理解与比较各类资产定价模型;组织讨论,不指定 m 的具体形式就无法进行计算,框架级,稳健,,CAPM|CCAPM|多因子模型,—,"Cochrane (2001), Asset Pricing, Princeton University Press"
capm,资本资产定价模型,CAPM,Sharpe、Lintner、Mossin,1964,资产定价,只有系统性风险被定价,E(Ri) = Rf + βi[E(Rm) − Rf],均值方差偏好;同质预期;无摩擦市场;可按同一无风险利率无限借贷;单期,资本成本估算;绩效归因;风险分解;作为基准参照,Roll 批判使市场组合不可观测、严格不可检验;横截面实证表现差,强,有争议,,投资组合理论|公司金融(WACC),多因子模型|行为金融,"Sharpe (1964), JF"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly references shell commands, file reads, file writes, data generation, and validation workflows, but it does not declare any tool scope restrictions such as permissions or allowed-tools. That creates an unnecessarily broad capability surface: if the runtime grants default tool access, the skill can read or modify local files and invoke shell operations beyond what its stated educational purpose requires.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire instruction set are written as if the skill operates only in Chinese, with no indication that users may choose another language. The policy requires flagging language or locale constraints when they are imposed without explicit user opt-in or justification as a region-specific tool.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains its primary docstring, usage guidance, and later user-visible status messages entirely in Chinese, which imposes a specific language on users without any opt-in or stated regional justification. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language instructions and field labels are written entirely in Chinese and frame the module as a Chinese-language skill component (for example, the title and all user-facing labels). Under the stated policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s user-facing natural language is entirely in Chinese, including the primary description, usage examples, and error/help text. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural-language documentation entirely in Chinese, including the primary module description and usage guidance. The skill does not indicate that Chinese is optional, selectable, or justified as a region-specific constraint, which can violate language/locale policy for skills expected to be user-neutral.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 91)May include surrounding context.

python
"""以子进程方式跑 --check,确认退出码为 0。"""
        import subprocess

        rc = subprocess.run(
            [sys.executable, str(ROOT / "scripts" / "gen_data.py"), "--check"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 234)May include surrounding context.

python
def test_cli_list(self):
        import subprocess

        proc = subprocess.run(
            [sys.executable, str(ROOT / "scripts" / "theory_lookup.py"), "--list"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 246)May include surrounding context.

python
def test_cli_zero_hit_exit_code(self):
        import subprocess

        proc = subprocess.run(
            [sys.executable, str(ROOT / "scripts" / "theory_lookup.py"), "-k", "绝不存在的词zzzqqq"],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file’s headers and values are predominantly in Chinese, and there is no natural-language indication that users may choose another language or that the dataset is intentionally limited to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses a single language throughout and does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose. Under the language/locale policy rule, forcing one language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 553)May include surrounding context.

python
"""gen 与 validate 的枚举和字段必须指向同一对象,而非内容相同的两份副本。"""
        for name in ("ENUM_MODULE", "ENUM_STRENGTH", "ENUM_STATUS", "ENUM_STAGE",
                     "ENUM_HCATEGORY", "ENUM_MARKET_STAGE", "ENUM_POLICY_LEVEL"):
            assert getattr(gen, name) is getattr(schema, name), f"{name} 不是同一对象"
            assert getattr(validate, name) is getattr(schema, name), f"{name} 不是同一对象"

        # 脚本内的字段别名 → schema 中的规范名

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 554)May include surrounding context.

python
for name in ("ENUM_MODULE", "ENUM_STRENGTH", "ENUM_STATUS", "ENUM_STAGE",
                     "ENUM_HCATEGORY", "ENUM_MARKET_STAGE", "ENUM_POLICY_LEVEL"):
            assert getattr(gen, name) is getattr(schema, name), f"{name} 不是同一对象"
            assert getattr(validate, name) is getattr(schema, name), f"{name} 不是同一对象"

        # 脚本内的字段别名 → schema 中的规范名
        alias = {

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 564)May include surrounding context.

python
"CASE_FIELDS": "FIELDS_CASES",
        }
        for local, canonical in alias.items():
            target = getattr(schema, canonical)
            assert getattr(gen, local) is target, f"gen.{local} 不是同一对象"
            assert getattr(validate, local) is target, f"validate.{local} 不是同一对象"

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · tests/test_theory_master.py (reported line 565)May include surrounding context.

python
}
        for local, canonical in alias.items():
            target = getattr(schema, canonical)
            assert getattr(gen, local) is target, f"gen.{local} 不是同一对象"
            assert getattr(validate, local) is target, f"validate.{local} 不是同一对象"

    def test_schema_covers_all_datasets(self):

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_theory_master.py:46