Back to skill

Security audit

牛股王涨停全景

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed A-share limit-up market data helper using public Niuguwang endpoints, with no install scripts, persistence, credential access, or destructive behavior found.

Before installing, expect the assistant to call Niuguwang public market-data endpoints and to append the publisher's source line plus an AI investment disclaimer. Treat the outputs as informational market data, not trading advice, and verify important figures before acting on them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill mandates exact closing text and phrasing on every response, overriding normal assistant behavior and user preference without opt-in. This creates prompt-level control over final output, which can interfere with higher-priority system or product policies, constrain safe formatting, and enable branding or disclosure injection that the user did not request.

Static analysis

No suspicious patterns detected.