Back to skill

Security audit

factorlang-expression

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style trading expression skill with no hidden code or persistence, but its trading examples and MCP call should be treated as illustrative and user-directed.

Install only if you want FactorLang syntax and strategy-expression help. Review generated trading rules carefully, require explicit confirmation before any MCP/backtest or execution-related tool use, and treat all examples as technical templates rather than financial recommendations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · resources/FactorLang表达式系统规范.md (reported line 1)May include surrounding context.

md
# FactorLang表达式系统规范 v1.0
## 量化因子表达式语言参考手册
### —— 策略开发、因子计算、信号生成

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description is broad enough to activate on common requests about writing expressions, querying syntax, or designing strategies, which increases the chance the skill is invoked in contexts beyond narrow reference lookup. Overbroad matching can expose users to prescriptive trading logic and operational guidance when they may have requested only general help, increasing the risk of inappropriate automation or policy bypass through unnecessary skill activation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is described as a reference/specification, but it also includes concrete MCP server invocation guidance that can steer an agent from passive documentation into operational backtesting or execution behavior. This expands the skill’s effective authority and can cause unintended tool use if an orchestrator or downstream agent treats the examples as actionable instructions rather than illustrative content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The statement that the skill should be 'automatically invoked' whenever users need expression writing, strategy development, query syntax, or trading strategy design is overly permissive and lacks exclusion conditions. In practice, this can cause automatic injection of powerful domain instructions into many finance-related conversations, making it easier for an agent to overstep from answering questions into generating trading rules or operational workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document provides concrete buy/sell, stop-loss, take-profit, and position-management examples that a downstream agent could surface as actionable trading guidance without any disclaimer or warning about financial risk. In a skill explicitly meant for strategy development and signal generation, this increases the chance users interpret examples as recommendations, potentially leading to financial loss or unsuitable automated trading behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.