Back to skill

Security audit

Fund Daily Report

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Chinese fund-report generator, but it embeds a third-party data-service login and can automatically use it without clear user control.

Review before installing. The publisher should remove and rotate the exposed JQData credentials, require users to supply their own credentials through environment variables or a secret manager, pin dependencies, and clarify which report sections are estimates rather than verified capital-flow or holdings data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
fund_daily_report.py:200
Finding

Hard-Coded JQData Account Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:15
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill’s declared purpose is a simple daily fund report, but the content describes broader behavior including external data collection from third-party services, proxy-based inference of capital flows, and the static finding indicates hardcoded JQData authentication not disclosed in the metadata. This mismatch is dangerous because it can cause operators to invoke the skill under false assumptions, leading to unauthorized third-party access, hidden credential use, or data handling that exceeds the stated business purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring states the output is top 30-day fund gainers, estimated fund inflow leaders, top industry inflows, and stocks with the most inferred fund buying. This diverges from the manifest's stated purpose of producing daily fund performance reports with NAV changes, market commentary, and portfolio updates, because the implementation is focused on market-wide ranking screens and inferred capital-flow analytics instead of per-fund daily summaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function comments and docstrings claim to retrieve the funds with the most inflow over 30 days and the stocks with the most fund buying, but the implementation ranks ETFs by 1-month performance and ranks stocks by成交额/涨跌幅-derived '资金关注度'. These statements actively overstate what the code measures and could mislead users into believing the output reflects actual fund capital flows or portfolio changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The fallback path imports a separate third-party service and embeds live JQData credentials directly in the skill. Hard-coded credentials in distributed code can be extracted and abused by anyone with access to the file, leading to unauthorized use of the external account, billing abuse, account suspension, or exposure of associated data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The line jq.auth('13918681158', 'Yindb1158') contains hard-coded authentication material with no disclosure or consent mechanism. This creates an immediate secret exposure risk: downstream users or attackers can reuse the credentials for unauthorized access, consume paid quotas, and potentially pivot into the associated third-party account.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation section uses general conditions such as '用户要求生成基金日报' and mention-based triggers like '天天基金', '基金排行', or '基金日报' without negative examples or constraints. These phrases can match ordinary discussion about funds, rankings, or data sources, making invocation boundaries unclear.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring, status messages, and report output are all written in Chinese, and the skill provides no option for the user to select another language. This constitutes a language/locale policy issue because the behavior is imposed rather than user-configurable or explicitly opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is effectively empty and provides no domain-specific invocation cues, trigger phrases, or exclusion conditions. In a manifest file, this lack of specificity can make activation behavior unclear and increases the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill description, headings, and usage notes are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific audience. Under the policy, locale or language constraints should be opt-in or clearly justified rather than implicitly enforced.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill generates daily fund performance reports with NAV changes, market commentary, and portfolio updates. The README describes additional behavior focused on cross-market rankings and analytics such as ETF fund inflows, concept-sector capital flows, and top stocks by fund position increases, which goes beyond a straightforward daily fund performance summary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructions, usage guidance, and output examples are presented only in Chinese, which effectively forces a specific language experience. There is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.