Back to skill

Security audit

Position Deviation Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese ETF deviation calculator that fetches public market data and does not show hidden persistence, credential access, account actions, or destructive behavior.

Install only if you want a Chinese-language ETF moving-average deviation helper for the four listed tickers. Do not treat its output as investment advice, and consider asking the publisher to narrow the trigger wording and remove or pin the unused Python dependency.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises broad activation phrases such as '持仓分析' and '加减仓建议', which can match many ordinary finance conversations and cause the skill to trigger outside narrowly intended use. In a financial-investment context, unintended invocation is riskier because the tool produces analysis that may be interpreted as investment guidance even with disclaimers, increasing the chance of inappropriate automation or over-reliance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger '生成今日投资分析报告' is highly generic and overlaps with common requests a user might make to any financial assistant, so this skill could be invoked when the user did not specifically request ETF moving-average deviation analysis. Because the skill is in an investment domain, accidental activation can steer responses toward a limited methodology and create misleading or unauthorized investment-oriented output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file’s user-facing docstring and returned guidance are entirely in Chinese, and the parser is built around Chinese trigger phrases such as “分析”, “计算”, and “帮我分析”. There is no indication that the skill is intentionally region-specific or that users may choose another language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The HTML document is explicitly marked with lang="zh-CN", and all visible content is presented only in Simplified Chinese. This creates a language/locale constraint without any user opt-in or explanation that the skill is intentionally region-specific, which matches the policy concern for forced language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is written entirely in Chinese and does not indicate that language selection is optional or that the skill is specifically intended for a Chinese-speaking audience. This can constitute a locale/language policy issue because it implicitly fixes the skill's presentation to one language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified as requests>=2.31.0, which permits installation of any future major or minor version and makes builds non-reproducible. This can unintentionally introduce vulnerable or incompatible releases through dependency drift or supply-chain changes, even if no issue is present at the time the file is reviewed.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest does not pin requests to a specific reviewed version, so it is impossible to verify whether installation will resolve to a release affected by known advisories. In a network-facing data analysis skill, requests is likely used to fetch external market data, which increases exposure to HTTP/client-side issues if a vulnerable version is installed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report timestamp is explicitly formatted with toLocaleString('zh-CN'), which hard-codes a specific locale in user-facing output. This is a natural-language/locale policy concern because the file does not offer a user opt-in or configuration mechanism, and no region-specific justification is documented in the code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.