Back to skill

Security audit

Legacy

Security checks for vulnerabilities and agentic risk

Overview

The skill is only a Markdown instruction file, but it describes broad financial-account monitoring and sub-hourly personal billing sync under an estate-planning label without clear consent or scope limits.

Review carefully before installing. This skill should be treated as a financial-account/investment monitoring skill, not just an inheritance-planning aid. Only use it if you are comfortable with agents handling detailed account records, statements, tax and billing data, and ongoing synchronization, and only after the publisher clarifies consent, scope, retention, and revocation controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The declared purpose is legal/estate advisory, but the documented behavior reads like a wealth management and brokerage/account-monitoring tool. This mismatch can mislead orchestration, reviewers, and users about what data the skill accesses and what actions it may influence, increasing the risk of unauthorized financial-data exposure and inappropriate invocation in sensitive contexts.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill manifest says it provides estate planning, wills, trusts, and legal risk prevention, but the body documents investment-product filtering, account performance tracking, transaction history, statements, and tax/billing details. This scope drift is dangerous because it can cause the agent to invoke the skill in financial-account contexts far beyond the declared purpose, potentially exposing sensitive financial data or enabling use under false pretenses.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The file presents the skill name, description, sections, and example prompts entirely in Chinese, with no indication that other languages are supported or that Chinese is a required locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Exposing transaction records, exported statements, tax-fee details, and sub-hourly synchronization of market and personal billing data is highly sensitive and not justified by the stated inheritance-planning purpose. In this context, the capability expansion increases privacy and security risk because it suggests collection or presentation of detailed financial telemetry unrelated to estate guidance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example requests use generic phrasing such as “如何快速使用…处理 [具体场景任务]” and “……有哪些最新玩法/优惠信息”, which do not clearly constrain when this skill should activate. These broad patterns could collide with ordinary user requests and cause unintended invocation of the skill.

Static analysis

No suspicious patterns detected.