Back to skill

Security audit

Investment Workflow

Security checks for vulnerabilities and agentic risk

Overview

This investment-research skill is mostly coherent, but it asks for broad local tool authority and can produce concrete buy/sell-style recommendations from broad triggers without enough scoping or user-facing safeguards.

Review this skill before installing if you use it for real financial decisions. It should be treated as research support, not personalized financial advice, and you should be comfortable with it using external market-data tools and WebSearch. The main install-time risk is the broad Bash/Exec/Read/Write permission set; prefer a constrained environment and avoid exposing private files, proprietary watchlists, or account-specific trading information.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:8
Finding

Excessive Agent Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:8
Vulnerability Type: Excessive permissions that violate the principle of least privilege
Risk Level: Medium

yaml
allowed-tools: [Bash, Read, Write, Exec, WebSearch]

Technical Analysis

The Skill grants general-purpose shell execution, process execution, filesystem reading, and filesystem writing through Bash, Exec, Read, and Write. Its documented investment-research workflow primarily requires market-data retrieval, analysis, and report formatting. No documented workflow step establishes a legitimate need for unrestricted command execution or general filesystem access.

This broad tool configuration increases the impact of untrusted instructions originating from user input, externally retrieved market data, or delegated Skills. If such content causes the Agent to invoke these tools, it could execute commands or access local files beyond the scope of the investment-analysis task.

The reviewed project does not contain a malicious command or direct instruction to abuse these permissions. Exploitation therefore depends on hostile or compromised content reaching the Agent while the excessive tools are available.

Attack Path

  1. The investment Skill is loaded with Bash, Exec, Read, and Write enabled.
  2. The workflow processes user-controlled input, externally sourced market information, or output from a delegated Skill.
  3. Malicious content embedded in one of those inputs instructs the Agent to invoke an unnecessarily authorized tool.
  4. If the Agent follows that instruction, Read could expose accessible local files, Write could alter accessible files, and Bash or Exec could run commands with the privileges of the hosting Agent process.
  5. The resulting activity could extend beyond investment research into unauthorized local-system access.

Impact Assessment

Successful exploitation could provide access to any files and co ...[truncated 492 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove Bash, Exec, Read, and Write from allowed-tools unless each capability is supported by a specific, documented workflow requirement.
  2. Prefer narrowly scoped market-data interfaces such as the declared data_layer or mcp-aktools operations rather than general-purpose shell execution.
  3. If report persistence is required, replace unrestricted Write access with a constrained output capability limited to a dedicated report directory, approved file types, and non-overwriting filenames.
  4. If local file reads are required, restrict them to explicit Skill resources or an allowlisted data directory.
  5. If command execution is unavoidable, use fixed commands with validated arguments, deny shell metacharacters, run inside a sandbox, and apply operating-system resource and network restrictions.
  6. Treat user input, web results, market data, and delegated-Skill output as untrusted content. Do not allow instructions embedded in that content to authorize tool use.
  7. Add tests confirming that the workflow completes using only the minimum required tools and that unauthorized filesystem paths and commands are rejected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes workflows that analyze whether assets or sectors are 'worth buying' and produce ranked recommendations, but it provides no warning that outputs are informational and not personalized financial advice. In the context of an investment skill, this omission materially increases the risk that users rely on the output for real financial decisions without understanding its limitations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase for the recommendation flow (e.g. '现在什么值得买?') is broad enough to match ordinary market conversation and can activate a workflow that produces ranked investment suggestions without clear gating. In a financial skill, accidental activation increases the chance of unsolicited or under-contextualized recommendations that users may treat as advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The '开会讨论' trigger is highly generic and lacks constraints tying it specifically to an investment-research session. This can cause the skill to activate in unrelated contexts and route users into a multi-view decision workflow that may generate financial analysis or recommendations unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description includes very broad Chinese trigger phrases such as '分析这个标的', '现在什么值得买', and '开会讨论投资', which are common conversational patterns and can cause unintended activation. In this skill, accidental invocation is more sensitive because the workflow is permitted to use WebSearch, Exec, Bash, and external data tools, potentially sending user investment context to outside systems without a clearly scoped opt-in at trigger time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The scenario table defines generic triggers like '分析 XX', '现在什么值得买?', '对 XX 行业怎么看', and '开会讨论', which overlap with ordinary chat and can activate the skill outside a clearly bounded investment context. Because later stages mandate data retrieval and a concrete buy/sell/hold/watch conclusion, unintended activation can escalate from harmless chat into external data access and high-stakes financial guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to call data_layer, mcp-aktools, and possibly other external retrieval mechanisms, but it does not clearly warn users that their investment queries and referenced tickers/sectors may be transmitted to external tools. This creates a transparency and privacy risk, especially for sensitive watchlists, proprietary research themes, or trading intentions that users may not expect to leave the local conversation context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill observation file is written in Chinese and the prompt examples and workflow labels assume Chinese as the required interaction language. There is no indication that users can choose another language or that the locale restriction is explicitly documented as a region-specific requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase '现在什么值得买?' is very broad and can appear in ordinary conversation without a clear request for a full investment-analysis workflow. In this skill, that ambiguity is more dangerous because invocation could cause the agent to initiate financial research and produce concrete recommendations in situations where the user did not explicitly intend that scope, increasing the risk of mis-triggering and inappropriate financial guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s natural-language content is entirely in Chinese and presents the interaction format, user request, and expected behavior only in that language. There is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-only regional context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is entirely written as a directive/change record in Chinese and includes instruction text describing expected behavior, but does not indicate that language choice is optional or constrained to a justified region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill observation record is written in Chinese and documents prompts, results, and workflow behavior exclusively in that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses only Chinese text for headings and instructions, which can amount to forcing a specific language without user opt-in. The policy allows locale constraints only when the file offers language choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s instructions and example interaction are entirely in Chinese and specify the expected handling/output in Chinese without indicating that language choice is optional. This creates a natural-language locale policy issue because the skill appears to enforce a specific language rather than offering user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire report template is written in Chinese, including headings, instructions, and placeholders, which implies the skill will generate output only in Chinese. The file does not indicate that language selection is optional or user-configurable, and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description, trigger phrases, examples, and output expectations are all presented exclusively in Chinese, implying a language constraint without user opt-in or an explicit region-specific justification. This can violate language or locale policy when a skill effectively forces one language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The activation description is entirely defined through Chinese trigger phrases and does not indicate that other languages are supported or that the user can opt into a preferred language. This can violate language/locale policy when a skill implicitly requires a specific language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a general investment workflow, but it does not indicate that Chinese is optional or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all operational documentation in a single language, which can amount to a language/locale policy violation when no user opt-in or alternative language option is provided. The file does not indicate that the skill is region-specific or that Chinese is required for compliance or domain constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.