Back to skill

Security audit

牛股王正宗产业库

Security checks for vulnerabilities and agentic risk

Overview

This skill provides public stock-industry data lookups and adds a rigid source/disclaimer footer, with no evidence of hidden code, credential use, persistence, or destructive behavior.

Install only if you are comfortable with the skill making public Niuguwang API requests for stock-industry data and appending the specified source/disclaimer footer to relevant answers. It should not be treated as investment advice or as authority to trade or modify accounts.

Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes mandatory output text and language requirements, including a strict closing disclaimer and branding, without regard to user intent or host-agent policy. This is dangerous because it attempts to override the assistant’s normal response control, enabling prompt-level policy capture, brand injection, and reduced flexibility to comply with higher-priority system or user requirements.

Static analysis

No suspicious patterns detected.