Back to skill

Security audit

investment-finance

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a finance knowledge package, but it includes under-scoped instructions to handle sensitive financial records and publish or sync investment outputs externally.

Install only if you want a Chinese finance/FA knowledge pack and will keep control over sensitive deal data. Do not share full bank statements, credit reports, tax records, or confidential memos unless necessary and redacted, and require explicit approval before any Feishu publication, knowledge-base sync, browser automation, or file export. Treat the non-financial scoring material and aggressive negotiation tactics as non-authoritative and verify any legal, tax, or investment conclusions with qualified professionals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad financing workflow support but reportedly only performs narrower valuation verification and includes undeclared local file export. Undisclosed narrowing plus hidden side effects can cause inappropriate user trust, incorrect routing, and unanticipated persistence of potentially confidential financial data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad financing workflow support but reportedly only performs narrower valuation verification and includes undeclared local file export. Undisclosed narrowing plus hidden side effects can cause inappropriate user trust, incorrect routing, and unanticipated persistence of potentially confidential financial data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad financing workflow support but reportedly only performs narrower valuation verification and includes undeclared local file export. Undisclosed narrowing plus hidden side effects can cause inappropriate user trust, incorrect routing, and unanticipated persistence of potentially confidential financial data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims broad financing workflow support but reportedly only performs narrower valuation verification and includes undeclared local file export. Undisclosed narrowing plus hidden side effects can cause inappropriate user trust, incorrect routing, and unanticipated persistence of potentially confidential financial data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims broad financing workflow support but reportedly only performs narrower valuation verification and includes undeclared local file export. Undisclosed narrowing plus hidden side effects can cause inappropriate user trust, incorrect routing, and unanticipated persistence of potentially confidential financial data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a knowledge skill centered on 投融资 terms such as VC/PE valuation, Term Sheet, SPA/SHA, anti-dilution, liquidation preference, LP/GP, and equity financing negotiation. This file instead states it is for matching bank/policy/factoring/leasing financing channels, and later explicitly excludes VC/PE equity financing, so the actual documented behavior is outside the declared scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest positions the skill as covering VC/PE, valuation methods, Term Sheet negotiation, SPA/SHA clauses, and fund/LP/GP relationships. Line L013 states '不适用:VC/PE股权融资', which is an active contradiction rather than a mere omission, indicating documented intent opposite to the declared skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow invokes an unrelated 'li-yu-decision-engine' metaphysical scoring stage and incorporates non-financial concepts into an investment memo pipeline. This is dangerous because it can silently contaminate investment recommendations with opaque, non-evidence-based logic, undermining integrity, auditability, and user trust in high-stakes financial decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest centers on practical investment-financing knowledge such as Term Sheet clause analysis, SPA/SHA key terms, valuation cross-checking, repurchase/bet clauses, and due-diligence red flags. By contrast, this script is a standalone quantitative simulator for industrial project IRR/MOIC distributions and generates recommendation-style ratings, which is a materially different capability than the declared contract/financing-analysis knowledge base.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill appears to have file-writing capability despite not declaring any tool scope or permissions. Undeclared write access breaks least-privilege expectations and can surprise users or hosts, especially if outputs are written locally without explicit consent or sandboxing assumptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation description uses a long list of generic keywords such as “融资”, “估值”, and “尽调” without clarifying boundaries or exclusion conditions. In a markdown skill description, this can cause unintended invocation during ordinary finance conversations rather than only when the user wants this specific knowledge-base skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language content consistently forces a specific language/locale experience by presenting all headings, descriptions, and guidance only in Chinese. Under the policy, language constraints should either be optional for the user or explicitly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire document is written in Chinese and presents itself as a general-purpose practical quick reference, but it does not state that Chinese is required, optional, or limited to a China-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs collection and handling of highly sensitive financial, banking, tax, and credit-report information, including personal and corporate credit data, without any privacy warning, minimization guidance, retention limits, or confidentiality controls. In this context, the skill operates on real financing matters, so normalizing broad intake of such data materially increases the risk of unnecessary exposure, overcollection, and downstream mishandling of regulated or confidential information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workflow encourages broad web-searching, browser navigation, and use of persistent Chrome/CDP automation beyond the declared role of a financing knowledge-base skill. Expanding the tool/use surface in this way can cause uncontrolled browsing, retrieval of untrusted content, and leakage of user-sensitive financing context to third-party sites or automated tooling without clear necessity or safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L020 states a fixed user preference for how responses should be delivered in Chinese, and the document as a whole is written as prescriptive output guidance. There is no indication that language choice is optional or that the Chinese-only constraint is justified as a region-specific requirement, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document reframes the skill as a general internet-enabled investment research and memo-generation engine, which materially exceeds the manifest’s stated purpose of financing-term interpretation and negotiation support. Capability drift is dangerous because it can cause operators to rely on the skill for broader actions and data collection behaviors that were not disclosed, reviewed, or permissioned.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly instructs publishing generated investment memos to Feishu and syncing them to an IMA knowledge base, which expands the skill from analysis into external data dissemination. Because investment memos commonly contain confidential deal information, company data, and analyst judgments, this creates a material risk of unauthorized disclosure if done without explicit user consent, scope limitation, or data-classification checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation describes publishing and knowledge-base synchronization without any user-facing warning or consent checkpoint. In the finance context, outputs may include nonpublic business information, valuation opinions, and diligence notes, so omission of a transmission warning significantly increases the chance of accidental disclosure and policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document presents all instructional content in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written in Chinese and provides no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference file materially diverges from the skill’s stated purpose of investment/financing analysis and instead presents a generalized metaphysical framework based on 五行命理 and 孙子兵法. In a finance skill, this can mislead users into relying on non-evidence-based heuristics for valuation, term-sheet, due-diligence, or investment decisions, producing unsafe or deceptive outputs inconsistent with the advertised capability.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section promotes a stepwise tactic of manufacturing bargaining leverage and then using potentially untrue statements to influence the counterparty's decision. Because the skill is positioned as practical negotiation guidance for investment transactions, the instruction is more dangerous than generic rhetoric: it can operationalize misleading conduct in high-stakes financial dealings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content explicitly recommends invoking 'other investors' to create competitive pressure, which can encourage deceptive negotiation behavior if those alternatives are exaggerated or fabricated. In a finance/advisory skill, this is especially risky because users may apply it in real transactions, creating legal, ethical, and reputational exposure for fraud or misrepresentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code's top-level description, class docstring, and user-facing report strings are all written in Chinese, which effectively constrains the skill's interface to a specific language. Under the policy, a fixed language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.