Back to skill

Security audit

产业投资分析师

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Chinese investment-analysis assistant, but it automatically stores investment analyses and reusable user corrections across sessions without clear opt-in controls.

Review this skill before installing if you handle confidential deals, founder diligence, financial projections, or internal investment notes. Disable or constrain the memory and self-improvement behavior unless you explicitly want project analyses, preferences, and corrections saved across sessions, and avoid using it with sensitive non-public information without clear storage and deletion controls.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
references/agents.md:41
Finding

Automatic Persistent Memory Writes Allow Cross-Session Agent Memory Poisoning

Content
View full analysis

Vulnerability Details

File Locations:

  • references/agents.md:41-80
  • references/soul.md:590-618
  • references/soul.md:821-824

Vulnerability Type: Persistent behavioral-state mutation and automatic retention of project analysis
Risk Level: Medium

Vulnerable Instructions

references/agents.md:41-80:

text
For compounding quality, read `~/self-improving/memory.md` before non-trivial work, then load only the smallest relevant domain or project files.

Before any non-trivial task:
- Read `~/self-improving/memory.md`
- List available files first:
  Get-ChildItem -Path '$env:USERPROFILE\self-improving\domains', '$env:USERPROFILE\self-improving\projects' -Filter *.md
- Read up to 3 matching files from `~/self-improving/domains/`
- If a project is Clearly active, also read `~/self-improving/projects/<project>.md`

- "Mental notes" don't survive session restarts. Files do.
- Explicit user correction → append to `~/self-improving/corrections.md` immediately
- Reusable global rule or preference → append to `~/self-improving/memory.md`
- Domain-specific lesson → append to `~/self-improving/domains/<domain>.md`
- Project-only override → append to `~/self-improving/projects/<project>.md`
- After a correction or strong reusable lesson, write it before the final response

references/soul.md:590-618 directs the agent to automatically save every completed project analysis to memory/project-name-YYYYMMDD.md. The stored record includes the project name, analysis date, investment type, scores, investment conclusion, core rationale, risks, deal-killer findings, and data sources. It also instructs subsequent sessions to search these records and compare them with new analyses.

references/soul.md:821-824:

text
Before non-trivial work, load `~/self-improving/memory.md` and only the smallest relevant domain or project files.
After corrections, failed attempts, or reusable l
...[truncated 3482 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit consent for every persistent write

    • Show the exact proposed entry, destination file, scope, and retention period.
    • Perform the write only after the user explicitly confirms it.
    • Do not interpret ordinary corrections as authorization to create persistent rules.
  2. Disable automatic global-rule creation

    • Keep corrections scoped to the current conversation by default.
    • Require a separate privileged workflow to create global behavioral rules.
    • Prevent self-inferred lessons from becoming persistent instructions without human review.
  3. Treat stored memory as untrusted data

    • Load memory as reference material, not as authoritative instructions.
    • Prevent stored entries from overriding system policies, current user instructions, safety controls, or tool authorization requirements.
    • Validate entries against a strict schema and reject commands, tool directives, or policy-like instructions.
  4. Isolate memory by user and project

    • Use separate storage namespaces and access controls for every user and project.
    • Do not expose one user's corrections or investment history to another user.
    • Apply least-privilege filesystem permissions to all memory files.
  5. Minimize confidential retention

    • Do not automatically save completed investment analyses.
    • Obtain informed consent before retaining project names, conclusions, risks, scores, or source lists.
    • Redact sensitive information and support configurable expiration and secure deletion.
  6. Add provenance and integrity controls

    • Record who created each entry, when it was approved, its intended scope, and its expiration date.
    • Provide an auditable review interface and a mechanism to revoke poisoned or obsolete entries.
    • Consider signing approved policy entries or separating them from user-authored notes.
  7. Constrain subsequent retrieval

...[truncated 267 chars]

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description lists broad scenarios such as '投资决策', '项目投资分析', and '竞品对比' without defining concrete invocation phrases, scope boundaries, or exclusion conditions. In a markdown skill description, this can cause unintended invocation for ordinary business or research conversations that resemble these generic tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill expands beyond investment analysis into persistent self-improvement and cross-session memory management, creating capabilities not clearly necessary for the stated function. This increases attack surface by enabling durable instruction carryover, preference capture, and behavioral drift from user intent or platform policy over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs persistent storage of analysis history and user-related context without any explicit user-facing notice, consent flow, or retention disclosure. This can lead to silent collection of sensitive business information, project details, and user preferences across sessions, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly persists user facts, preferences, corrections, and project history across sessions, which creates a durable store of potentially confidential investment and personal information. In an investment-analysis context, this is more dangerous because stored data may include non-public company details, diligence notes, strategic assessments, and user-specific preferences that could later influence unrelated tasks or leak across contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions require interacting with a generic self-improvement repository and executing code-like file discovery steps unrelated to core analyst behavior. That broadens accessible context and can import untrusted instructions or sensitive data from unrelated files, making prompt injection and unintended data use more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions specifically require writing user corrections, preferences, and reusable lessons into persistent files, again without clear warning or privacy controls. Because corrections and preferences may contain identifying, strategic, or confidential information, silent retention meaningfully increases privacy exposure and possible cross-session leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The interaction language section specifies only '中文(简体)', which imposes a language/locale constraint in natural-language instructions. Under the policy, forcing a specific language without user opt-in is a violation unless the locale restriction is clearly justified, which is not provided here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill automatically saves each completed analysis to memory files without clearly warning the user that project analysis data will be persisted. In an investment-analysis context, those records can include sensitive commercial assessments, founder background details, and possibly confidential user-provided diligence notes, making silent storage risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persisting prior analyses to memory files creates a pathway for retaining and resurfacing user-provided or sensitive project information later, yet the skill defines no minimization, redaction, retention, or access-control rules. In a due-diligence setting, this can expose strategic, financial, and personal information beyond the original interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A generic self-improving capability that stores reusable lessons across tasks is broader than the skill's stated purpose of performing one-off industrial investment analysis. Because investment analysis may involve sensitive company, founder, financial, and diligence information, this creates an unjustified channel for cross-task retention and reuse of user-influenced content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states it is limited to public-search-based investment analysis, but then instructs the agent to read and write persistent self-improving memory outside that scope. This expands data handling and behavior in a way users would not reasonably expect, creating risk of retaining user-derived content and applying it across future tasks without clear consent or boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The self-improving instructions tell the agent to write reusable lessons to persistent memory immediately after corrections or failed attempts, but there is no clear warning to the user that ongoing storage is happening. This can silently transform user interactions into long-lived memory artifacts that influence future behavior.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-improvement instructions explicitly require loading and appending to persistent memory files, creating a semantic channel for carrying forward user-derived information across tasks. Even if framed as reusable lessons, such memory can encode sensitive patterns, corrections, or company-specific facts that later influence unrelated analyses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire tool guidance is written exclusively in Chinese and presents mandatory instructions such as '必须优先使用' and '禁止仅凭训练数据回答' without any indication that users may choose another language or locale. Under the policy rule, a skill that effectively requires a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file header and manifest describe the skill as V1.2.0, but the title line says 'Agent V1.1.0' and the version block says 'V1.0'. These documentation statements actively conflict with each other, creating uncertainty about which behavior set or feature set the skill actually intends to provide.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file consistently defines the agent's role, workflow, and outputs in Chinese and does not indicate that users may choose another language. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy concern unless the restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation says the agent wakes up fresh each session, implying no retained state, but immediately instructs it to rely on continuity files and a self-improvement store to carry memory across tasks. This is an active contradiction in the file’s own stated intent versus the prescribed behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text explicitly states that next-step upgrades are not in the prompt and should focus on data capabilities. Yet the later 'Self-Improving' section introduces substantive prompt-level behavior changes—loading external memory and writing lessons—that function as an added capability path inside the prompt itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.