Security audit
A股观点拆解
Security checks for vulnerabilities and agentic risk
Overview
This is a text-only financial analysis skill that structures long macro or news material into A-share hypotheses without installing code, requesting credentials, or adding hidden behavior.
Reasonable to install as an analysis aid. Treat its outputs as hypotheses, not investment advice, and separately review any downstream market-data, portfolio, brokerage, or action-routing tools before allowing them to use credentials or place trades.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
