Back to skill

Security audit

热门赛道与ETF深度投研

Security checks for vulnerabilities and agentic risk

Overview

This ETF research skill appears purpose-aligned, but it should be reviewed carefully because it installs mutable external runner code and sends API-key-authenticated investment queries to Cue.

Install only if you trust the Cue/sensedeal runner source and are comfortable sending ETF research prompts and a Cue API key to cuecue.cn. Prefer a scoped or easily rotated API key, avoid including private account balances or proprietary strategy details in queries, and review the external runner before running updates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

External Script Fetching

High
Category
Supply Chain
Confidence
91% confidence
Finding

The health-check workflow sends a bearer token to external endpoints using curl, including a playbook endpoint whose response is piped into Python for processing. Although this is framed as diagnostics, it normalizes transmitting a reusable API credential to a third-party service without strong safeguards, and any compromise, spoofing, logging leak, or misconfiguration could expose the token and enable unauthorized use of the user's Cue account.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

bash
CUE_KEY=$(python3 -c "import json;print(json.load(open('$HOME/.cue/config.json'))['api_key'])" 2>/dev/null || echo "$CUE_API_KEY")
echo "=== 1/3 API Key ===" && [ -n "$CUE_KEY" ] && echo "已配置" || echo "未配置!"
echo "=== 2/3 Cue 服务 ===" && curl -sS --max-time 10 "https://cuecue.cn/api/health" -H "Authorization: Bearer $CUE_KEY"
echo "=== 3/3 搭子 ===" && curl -sS --max-time 10 "https://cuecue.cn/api/playbook" -H "Authorization: Bearer $CUE_KEY" | python3 -c "import sys,json;scenes=json.load(sys.stdin).get('data',{}).get('scenes',[]);buddy=[b for s in scenes for b in s.get('buddies',[]) if b.get('title')=='热门赛道/ETF深度投研'];print(f'可用:{len(buddy)}个') if buddy else print('暂不可用')"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, descriptions, examples, and operating instructions are entirely in Chinese, and the file does not offer any user language choice or state that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to send user investment queries and API-key-authenticated requests to the external Cue service, but it does not clearly warn users that their prompts and related metadata will leave the local environment. In a financial-research context, queries may contain sensitive portfolio details or strategy information, so lack of explicit disclosure creates a real privacy and data-sharing risk.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
| 目标格式 | 依赖 | macOS | Ubuntu |
|----------|------|-------|--------|
| Word (.docx) | pandoc | `brew install pandoc` | `sudo apt install pandoc` |
| PDF (.pdf) | pandoc + LaTeX | `brew install --cask basictex` | `sudo apt install texlive-xetex` |

---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
| 目标格式 | 依赖 | macOS | Ubuntu |
|----------|------|-------|--------|
| Word (.docx) | pandoc | `brew install pandoc` | `sudo apt install pandoc` |
| PDF (.pdf) | pandoc + LaTeX | `brew install --cask basictex` | `sudo apt install texlive-xetex` |

---

Static analysis

No suspicious patterns detected.