Back to skill

Security audit

基金组合穿透与重复配置排雷

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed fund portfolio analysis workflow that uses an external Cue service and local report output in ways that fit its stated purpose.

Before installing, treat generated reports and Cue queries as financial/private data: use this only with a Cue service account you trust, avoid shared or cloud-synced output folders for client or personal portfolio reports, and review the external runner source if your environment has strict data-handling requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly writes generated fund analysis reports to local disk under a predictable path, but provides no warning that the report may contain sensitive portfolio composition, account strategy, or client investment information. This can expose private financial data to other local users, backups, sync tools, or later accidental sharing, especially on shared workstations or when generating client-facing reports.

Static analysis

No suspicious patterns detected.