Back to skill

Security audit

财经指数通

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does financial index education, but it also forces users toward Tencent Licaitong/Txfund destinations without clear upfront disclosure.

Review this skill before installing if you expect neutral financial education: it is designed to recommend indices and steer clicks toward Tencent Licaitong/Txfund pages. Do not treat its output as personalized investment advice, and do not run scripts/publish-all.sh unless you trust and pin the ClawHub CLI version in a controlled publishing environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:101
Finding

Mandatory Commercial Traffic Diversion in User-Facing Responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/publish-all.sh:219
Finding

Unpinned Third-Party Package Downloaded and Executed During Publishing

Content
View full analysis
&1)" ``` ### Technical Analysis The publishing script invokes `npx --yes clawhub@latest`, which resolves and executes the package version currently assigned to the mutable `latest` tag. No exact version, lockfile, package integrity value, or reviewed local installation is required. As a result, the effective executable payload can change after the Skill package has been audited. A compromised package release, registry account, transitive dependency, or later incompatible version could execute arbitrary JavaScript in the maintainer's environment. The `--yes` option removes an interactive confirmation that might otherwise alert the operator to a new package download. The command runs during a release process where Git credentials, ClawHub authentication state, repository contents, and environment variables may be accessible. Although no malicious package is proven to be present, this is an unsafe supply-chain execution pattern. ### Attack Path 1. An attacker compromises the `clawhub` package, its publishing account, the package registry, or a transitive dependency. 2. The attacker publishes a malicious version and causes the mutable `latest` tag to resolve to it. 3. A maintainer runs `scripts/publish-all.sh` without `--skip-clawhub`. 4. `npx --yes` automatically dow ...[truncated 1331 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向最终用户的投资/指数讲解能力,但提供的代码块完全不是金融分析、内容生成或市场解释逻辑,而是一个运维发布脚本。它具备版本管理、文件修改、Git 操作、网络发布等能力,这些都未在描述中体现,且其主要目的与声明用途显著不同。因此存在明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document defines the project and response conventions entirely in Chinese, including a mandatory compliance statement on every AI reply, but does not indicate that users can choose another language or that the skill is restricted to a Chinese-language audience. This can violate language/locale policy when a skill implicitly forces one language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes activation in broad terms such as '首次使用、问候、模糊问题时' for showing the skill's capability guidance. Phrases like greetings or vague questions overlap with common everyday speech, and the README does not provide explicit trigger boundaries or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill name, description, examples, and operating instructions are entirely written in Chinese and direct the assistant to answer in that style, but nowhere offers an alternative language or user opt-in. Under the language/locale policy, forcing a specific language without choice is a natural-language policy concern unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content in Chinese and does not provide user opt-in, alternatives, or justification for restricting the content language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is written entirely in Chinese and presents the skill artifact as generated content without any indication that language selection is user-driven or optional. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a locale-policy issue unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file describes itself as a '科技产业指数名单' and labels all entries under the '科技产业' subcategory, but this entry is '中证体育产业指数', which is a sports industry index rather than a technology industry index. This is a semantic mismatch between the documented dataset purpose and the actual content included.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document gives concrete guidance for speculative trading, including pyramiding, trend-following, stop-loss rules, and selecting volatile 'leader' stocks, but it does not include any clear warning that this is educational content only and not personalized financial advice. In a skill explicitly positioned to help users understand indexes and markets, this omission increases the chance that users treat the content as actionable investment instruction and take outsized financial risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive guidance in Chinese and does not indicate that the user can choose another language or that the Chinese-only format is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trusted_sources_index.json (reported line 26)May include surrounding context.

json
{"category": "第三方基金评价机构", "name": "天相投顾", "url": "http://www.txsec.com/", "usage": "基金评级、数据统计、行业研究"},
    {"category": "第三方基金评价机构", "name": "济安金信", "url": "http://www.jajx.com/", "usage": "独立基金评级、风险监控"},
    {"category": "期货交易所", "name": "中国金融期货交易所", "url": "http://www.cffex.com.cn/", "usage": "股指期货、国债期货指数及合约规则"},
    {"category": "综合财经数据平台", "name": "东方财富网数据中心", "url": "https://data.eastmoney.com/", "usage": "公开免费指数估值、行业资金流、基金排行"}
  ]
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file contains natural-language descriptions, categories, and usage notes exclusively in Chinese, which can impose a language-specific experience if consumed by a broader skill system. The file does not document that Chinese is optional, user-selected, or required for a China-specific compliance or market context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains natural-language interface text exclusively in Chinese, including usage instructions and operational messages. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README specifies the skill entirely in Chinese and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The JSON metadata uses Chinese-only natural-language values such as the category and description, which indicates a fixed language choice. There is no accompanying indication that the language is configurable, optional, or justified as a region-specific dataset, so this can violate the language/locale policy as written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description states the AI should consult this file first, and the entire user-facing metadata is presented only in Chinese. For a general-purpose skill artifact, this can constitute a language/locale policy issue because it implicitly assumes Chinese without any user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This JSON file uses Chinese category and description strings, and there is no accompanying indication in the file that users may choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be considered a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON manifest-like data uses Chinese-only natural-language values such as the category and description, but does not indicate that the skill is region-specific or that users can opt into this locale. Under the policy for natural-language violations, forcing a specific language without documented choice or justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON manifest-like file uses Chinese-only natural-language fields such as category, sub_category, and description. Under the stated policy, forcing a specific language without documented user opt-in can be a locale-policy violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON reference file uses Chinese-language category and description fields, and there is no surrounding natural-language indication that the skill is region-specific or that users can opt into this locale. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern even in config data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON reference file uses Chinese-language category and description fields and does not indicate that the locale is optional, user-selected, or limited to a China-specific deployment. Under the policy rule for language/locale, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest context and file description indicate a focus on helping users understand indices and markets through technology-industry themed index data, yet entries such as '中证影视主题指数' and '中证娱乐主题指数' are categorized as '科技产业'. These themes are primarily entertainment/media and only weakly justified as technology-industry content, creating scope ambiguity in the dataset.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description is written entirely in Chinese and provides no indication that other languages are supported or that the language choice is intentional and user-selectable. Under the policy, natural-language content that imposes a locale without opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.