Back to skill

Security audit

Global Economy Daily

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed daily market-report skill, but it mixes live price pulls with static commentary while presenting the report as real-time and includes broad outbound-send instructions.

Review before installing. Treat the analysis sections as templated/static unless rewritten, confirm or replace all QQ/Feishu recipients, add an explicit confirmation step before any send, and only create the LaunchAgent if you want automatic recurring external messages.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The report header explicitly claims 'Yahoo Finance(实时)', but the bulk of the attribution, geopolitical analysis, and outlook are hardcoded narratives unrelated to fetched market data. This can mislead recipients into believing all analysis is current and data-driven, creating integrity and trust risks that are especially problematic for financial or geopolitical decision-making.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manual trigger phrase “发送每日洞察” is broadly defined and does not describe any authorization, confirmation, or context checks before sending outbound messages. In an agent environment, overly permissive natural-language triggers can be invoked unintentionally or by another prompt/context, causing unauthorized actions such as message delivery or data publication.

Static analysis

No suspicious patterns detected.