Back to skill

Security audit

semiconductor-value-investing

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language semiconductor investing research and writing framework with no executable code, but users should review financial conclusions before relying on or publishing them.

Install this if you want a Chinese semiconductor value-investing writing framework. Treat its outputs as research drafts, not personalized financial advice; verify current prices and financial data, and approve any Xueqiu/Tencent Docs publishing or local archiving explicitly.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The skill metadata and body are written to operate in Chinese and frame output style accordingly, but there is no indication that the user explicitly opted into Chinese-only responses. This can override user language preference, reduce usability, and create prompt-level steering that conflicts with the caller's requested language or accessibility needs.

Static analysis

No suspicious patterns detected.