Back to skill

Security audit

光通信投资分析框架(中文版)

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent investment-analysis reference, but its optional update mode can use a logged-in browser session and edit local knowledge files with unclear scheduling and consent boundaries.

Install only if you are comfortable with an agent using your logged-in Xueqiu/browser session during the update workflow and modifying this skill's local reference files. Treat updates as manual-only, confirm the exact URLs and files before running them, and treat the investment material as time-sensitive opinion rather than verified financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill states that self-iteration only runs on explicit user trigger, but later also recommends periodic checking. That inconsistency can cause an agent to perform browsing and knowledge-update actions without a fresh user request, expanding behavior from passive analysis into semi-autonomous external access and file modification.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes many broad domain keywords such as 光通信, 光模块, CPO, and related terms, which can cause the skill to activate in ordinary discussion rather than when the user explicitly wants this specific workflow. In a skill with optional browsing and self-update behavior, overbroad activation increases the chance of unintended tool use, misleading analysis scope, or unexpected file-changing behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The self-update activation conditions are internally inconsistent: one section says updates occur only on user request, while another section suggests timed checks. Ambiguous activation rules are dangerous because they weaken user-consent boundaries around external browsing, use of an existing logged-in browser profile, and local reference-file edits.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to modify local reference files and an update log as part of the workflow, but it does not provide a strong user-facing warning or require confirmation immediately before making those changes. Because the same workflow also involves external content ingestion from Xueqiu and use of a logged-in browser profile, silent persistence of imported content raises integrity, provenance, and unexpected-side-effect risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.