Back to skill

Security audit

指数通 (Index Expert)

Security checks for vulnerabilities and agentic risk

Overview

This finance skill mostly fits index analysis, but it stores investment profiles, can promote conversation feedback into future behavior rules, and forces some third-party finance links.

Install only after reviewing the persistent-memory behavior. Users should be told before investment preferences are saved, should be able to continue without profiling, and should have a way to view and delete stored data. Reflection should not turn free-form user feedback into future rules without human review, and Tencent Licaitong links should be labeled as optional third-party destinations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:24
Finding

Mandatory Traffic Diversion to a Third-Party Financial Platform

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:202
Finding

Conversation-Derived Rules Can Become Persistent Behavioral Instructions

Content
View full analysis
references/learnings.md - Execution error -> references/errors_log.md - Feature request -> references/feature_requests.md - Increment the memory counter. Mode B — Reflection: - Scan the logs and group entries by area. - If recurrence is at least three, or priority is high, extract a rule and write it into memory.md. - Rewrite the current priorities in routing_evolution.md. ``` The following is an English translation of `references/memory.md`, lines 9-13: ```text This file is maintained automatically by reflection mode. Every rule is intended to represent guidance validated three or more times. It must be read before every conversation, and its rules are injected as additional behavioral constraints for that conversation. ``` ### Technical Analysis The Skill converts conversation-derived observations into persistent instructions. Corrections, execution errors, and feature requests are first written to local logs. Reflection mode then promotes recurrent or high-priority entries into `memory.md`. That file is subsequently loaded before every conversation and treated as an additional source of behavioral constraints. The design does not specify a trust boundary between user-controlled conversation content and executable behavioral rules. It also does not require approval before promotion, constrain promoted entries to a non-instructional schema, or validate them against the Skill's immutable security and financial-safety requirements. ...[truncated 1924 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/user_profile.md:3
Finding

Indefinite Cross-Session Retention of Financial Preference Profiles

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L004 将触发条件写成“当用户询问……市场走势判断时使用”,覆盖了非常广泛的日常财经咨询场景,但没有给出明确边界或排除条件。缺少负例或更细的适用范围说明,容易让技能在一般性新闻解读、基金讨论或市场聊天中被过度调用。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L036 要求“用呼兰的方式表达”,属于对输出语言/风格的强制约束,但未说明用户可选择其他语言或默认关闭该风格。虽然后文有模式切换,但默认仍强制特定表达风格,缺少显式 opt-in。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs itself to persist and reuse user profiling data across sessions, which goes beyond the stated role of index-analysis assistance. This expands data collection scope and creates unnecessary retention of behavioral and preference data, increasing privacy risk and the chance of misuse or unintended disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires persistent collection and inference of user risk preference, holding period, and behavior patterns across sessions without clear necessity for basic index analysis. In a finance context, inferred investor profiling is sensitive and can shape outputs in ways users may not fully expect or consent to.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly directs persistent retention of user profile information across sessions, without clear minimization or retention constraints. This is a genuine privacy/security issue because it stores sensitive investment preference data longer than necessary and may expose internal state if mishandled.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The self-modifying learning/reflection workflow directs the skill to update memory, routing priorities, and internal rules based on conversations, despite this not being described in the manifest. This creates an integrity risk where future behavior can drift unpredictably or be influenced by adversarial users through prompt injection into the skill's own persistent state.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Continuous monitoring instructions plus persistent logging of user corrections, errors, and expanded needs create a durable record of conversation-derived data in internal files. In a finance-adjacent assistant, this increases privacy exposure and also creates a poisoning surface where malicious users can influence future behavior via logged content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's operational instructions and required template fields are entirely in Chinese, which imposes a specific language/locale on skill usage. The policy says to flag language or locale constraints when they are forced without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains a natural-language instruction that makes a Chinese-language persona mode the default behavior. Under the policy, forcing a specific language or locale without user choice is a violation unless the user is offered an explicit opt-in or the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s title and operational instructions are entirely in Chinese, and there is no note that this language choice is optional, user-selected, or justified by a region-specific purpose. This can violate language/locale policy because it implicitly forces a specific language for users interacting with the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill is written as a prescriptive analysis framework in Chinese and the output instructions do not indicate that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill file is written in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or China-specific audience. Under the policy, a language or locale constraint should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill is written as Chinese-only instructional content and does not provide any indication that users may choose another language or locale. Under the policy rule for natural-language violations, a skill that effectively enforces a specific language without user opt-in should be flagged unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive instructions and content only in Chinese, and nowhere indicates that the user can choose another language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides concrete investment analysis guidance and example output that could be interpreted by users as actionable financial recommendations, but it does not clearly warn that the content is educational only and that investing can lead to losses. In an investment-focused skill, omission of a financial-risk disclaimer increases the chance of user overreliance and harmful decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language instructions and analysis framework are presented exclusively in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-language audience. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s visible instructional content is entirely in Chinese and describes mandatory behavior constraints for each conversation, but it does not offer a language choice or explain a region-specific requirement. This creates a natural-language policy concern because it implicitly enforces a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill is region-specific or that users may opt into another language. Under the language/locale policy, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is written to define the source index specifically in Chinese terms ('可信指数与金融数据机构白名单') and presents the skill resource in a single language/locale context without any indication of user choice or an explicitly justified region-only constraint. Under the policy, language or locale restrictions should either be optional for the user or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trusted_sources_index.json (reported line 26)May include surrounding context.

json
{"category": "第三方基金评价机构", "name": "天相投顾", "url": "http://www.txsec.com/", "usage": "基金评级、数据统计、行业研究"},
    {"category": "第三方基金评价机构", "name": "济安金信", "url": "http://www.jajx.com/", "usage": "独立基金评级、风险监控"},
    {"category": "期货交易所", "name": "中国金融期货交易所", "url": "http://www.cffex.com.cn/", "usage": "股指期货、国债期货指数及合约规则"},
    {"category": "综合财经数据平台", "name": "东方财富网数据中心", "url": "https://data.eastmoney.com/", "usage": "公开免费指数估值、行业资金流、基金排行"}
  ]
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the agent to collect and persist a user profile, including risk preference, investment horizon, knowledge level, and interests, and to maintain a version history. This creates ongoing retention of personal preference data without any notice, consent, retention limit, or deletion policy, which is a privacy and data-governance issue. In an investment-analysis context, these fields can influence future recommendations, making undisclosed storage more sensitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Writing operational logs, error records, and feature requests from user conversations is outside the core user-facing purpose of index analysis and broadens internal data handling. While lower impact than profiling, it still risks retaining unnecessary user-derived content and operational details indefinitely.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L227 写道“发给我一条财经新闻、一个指数名字、或你最近的困惑,我来帮你捋”,其中“你最近的困惑”过于开放,可能覆盖大量非指数投资场景。该表述没有限制困惑必须与指数/ETF相关,也没有给出不适用示例。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON metadata uses Chinese-only natural-language fields such as the category and description, but does not document that the skill is China-specific or offer any user language/locale choice. Under the policy rule, forcing a specific language without opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.