Back to skill

Security audit

李录文明分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small Chinese-language investment-analysis framework with a clear China-focused thesis and no hidden system access, persistence, or data exfiltration behavior.

Install this only if you want a Chinese-language, China-focused long-term investment analysis lens. Treat its conclusions as framework-based commentary, not personalized financial advice, and ask the agent to consider your market, jurisdiction, risk tolerance, and counter-scenarios before acting on any investment output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README is written entirely in Chinese, including headings, usage instructions, and descriptions, with no indication that users may choose another language or that the skill is region-specific. This creates a natural-language policy concern because it imposes a specific language on all users without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill presents a region-specific investment conclusion ('中国是最大机会') as a core principle without asking for the user's market scope, risk profile, or geographic focus. In an investment-analysis skill, this can bias outputs toward a predetermined conclusion and cause unsuitable or misleading recommendations for users outside that context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The closing slogan again promotes China as the 'biggest opportunity' in absolute terms, reinforcing a built-in geographic investment bias. Because this appears in a persuasive closing statement rather than a conditional analysis section, it increases the chance that the agent will steer users toward one jurisdiction regardless of their objectives or suitability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python skill presents its title, docstrings, prompts, and user-facing output exclusively in Chinese. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in, and this file provides no alternative language path or justification for the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire template is written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, a skill that forces a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.