Back to skill

Security audit

A股观点拆解

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only financial analysis skill that structures long macro or news material into A-share hypotheses without installing code, requesting credentials, or adding hidden behavior.

Reasonable to install as an analysis aid. Treat its outputs as hypotheses, not investment advice, and separately review any downstream market-data, portfolio, brokerage, or action-routing tools before allowing them to use credentials or place trades.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.