Back to skill

Security audit

题材库分析师 (A-Share Theme Analyst)

Security checks for vulnerabilities and agentic risk

Overview

This skill provides read-only A-share theme analysis using public market-data sources, with disclosed outbound API calls and investment-risk disclaimers.

Install only if you are comfortable with the agent making read-only requests to public financial-data and search providers for the themes or stocks you ask about. Review optional AKShare and any separately suggested search skill before installing them, and treat all generated market analysis as informational rather than financial advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.