Back to skill

Security audit

A股观察循环

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, instruction-only A-share market checklist helper with no executable code, credential access, persistence, or hidden data movement.

Before installing, understand that this skill is meant to structure stock-market review checklists, not execute trades. Only share holdings or portfolio details you are comfortable providing, verify real-time market data independently, and treat its pass/fail actions as decision-support rather than financial advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation cues are generic user phrases such as '把观察项落下来' and '用户要每日复核框架', which can match many ordinary finance/planning requests and cause the skill to trigger when the user did not explicitly ask for this workflow. Over-broad activation can hijack routing, override more suitable skills, and steer responses into a rigid checklist format that may not fit the user's intent or available data.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill metadata description is written only in Chinese and the finding indicates language forcing without user opt-in, which can bias selection and output behavior toward Chinese even when the user has not requested that language. This is primarily a safety and usability issue: it can reduce transparency, confuse users, and interfere with proper consent or correct routing in multilingual environments.

Static analysis

No suspicious patterns detected.