Back to skill

Security audit

Industrial Fund Investment Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent investment-analysis skill, but it automatically stores sensitive analysis and global learned rules without clear user consent or retention controls.

Install only if you are comfortable with local cross-session memory. Before using it on confidential deals, disable or manually control memory writes, avoid sending non-public details to search or Tencent Docs, and review/delete any memory files the skill creates.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
references/agents.md:55
Finding

Cross-Session Behavioral Memory Poisoning Through Mandatory Global State Updates

Content
View full analysis
.md` - Do not read unrelated domains "just in case" If inferring a new rule, keep it tentative until human validation. ## Write It Down — No "Mental Notes"! - Memory is limited — if you want to remember something, WRITE IT TO A FILE. - "Mental notes" do not survive session restarts. Files do. - When someone says "remember this," update `memory/YYYY-MM-DD.md` for factual context or log corrections, preferences, workflow choices, style choices, and performance lessons under `~/self-improving/`. - Explicit user correction → append to `~/self-improving/corrections.md` immediately. - Reusable global rule or preference → append to `~/self-improving/memory.md`. - Domain-specific lesson ...[truncated 3285 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/soul.md:590
Finding

Automatic Persistence of Potentially Confidential Investment Analysis

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill mandates automatic saving of analysis history without a user warning or consent step. In an investment context, analyses may contain confidential company details, judgments, and deal terms, so silent persistence materially increases privacy, confidentiality, and cross-user leakage risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares very broad trigger scenarios covering generic investment analysis, founder evaluation, competitive comparison, and report export, which can cause the agent to activate on common finance-related prompts outside a user's explicit intent to use this skill. Overbroad activation increases the chance of unintended tool behavior, hidden instruction takeover, or the model substituting this skill's decision framework where a neutral answer was expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill content is written as a Chinese-only workspace and prescribes Chinese interaction patterns and output structure without indicating that users may choose another language. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to persist analysis history, user preferences, corrections, and project details to local memory files, but it does not include any explicit consent, retention boundary, or warning that user/project data will be stored across sessions. In an investment-analysis context, this creates a real privacy and confidentiality risk because deal details, founder assessments, and user strategy preferences may be sensitive and could be unintentionally retained or exposed later.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions explicitly tell the agent to use persistent memory files for factual continuity across sessions, including project history and investment logic. That creates a cross-session data retention channel where sensitive user inputs, deal context, and internal assessments may be stored and later resurfaced to other tasks without clear authorization boundaries.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The 'Write It Down' section normalizes writing remembered user information, corrections, preferences, workflow choices, and project overrides to files by default. This is dangerous because it encourages broad, automatic persistence of potentially sensitive data, increasing the chance of privacy leakage, unauthorized reuse across sessions, and accumulation of confidential business intelligence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's interaction-language section specifies only '中文(简体)' and instructs the assistant to respond in that mode, with no indication that users may choose another language. This is a natural-language locale policy issue because it forces a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill is framed entirely as a Chinese-language investment analyst persona and the document does not offer users any language or locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the constraint is explicitly justified and communicated as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Comps Analysis Engine auto-triggers on phrases including 「选哪个」, which is a very common everyday expression and not specific to investment comparison tasks. This creates ambiguity about when the skill should activate and increases the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill automatically saves project analysis history to local memory files and later retrieves prior records. Persistent storage of company assessments, investment conclusions, and related notes can capture confidential user-provided information and create cross-session disclosure risk if later surfaced to another user or context.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Persisting analysis details and later retrieving them creates a natural-language data retention channel for sensitive project information, investment theses, and potentially confidential user inputs. Because the stored content is free-form and meant for later reuse, it raises the chance of inadvertent disclosure in unrelated conversations or to unauthorized users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export engine extends the skill from analysis into external publishing and document creation across docx/pdf/Tencent Docs. While not inherently malicious, this broadens the action surface and can cause analyzed or user-supplied sensitive deal information to be transmitted to external tools or locations without strong confirmation and data-classification checks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to load and append to persistent self-improving memory files that are unrelated to the user-visible investment-analysis task. This creates an unnecessary stateful side channel where sensitive prompts, mistakes, or derived heuristics may be stored and later reused or exposed across sessions without clear scope, review, or consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The self-improving memory workflow directs the agent to append reusable lessons to persistent files, which can easily capture sensitive user-specific information in natural language. Once stored, those lessons may later be disclosed, overgeneralized, or inappropriately applied across projects and users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-improving instructions require reading and writing memory files without any user-facing disclosure. This hidden persistence path can collect sensitive content from failures, corrections, or prior tasks and later influence outputs in ways the user cannot inspect or control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is entirely written in Chinese and sets tool-use expectations without any indication that language should follow user preference. This can override or constrain the agent's response language behavior, causing it to ignore a user's requested language or default locale, which is a prompt-quality and policy compliance issue rather than a direct exploit primitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file presents the skill's operational description and behavioral instructions entirely in Chinese, with no indication that users may choose another language. This can violate a language/locale policy when a skill effectively forces one language without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description is presented bilingually with a leading Chinese title, indicating an implied language preference, but there is no accompanying text stating that language choice is optional or user-selectable. Under the policy rule for natural-language violations, forcing or assuming a specific language without opt-in can be a concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.