Back to skill

Security audit

智能投资简报生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent stock-report generator, but it needs review because crafted stock inputs can be executed as local shell commands and an external search script receives the full environment.

Review before installing. Do not use this skill with untrusted stock names or symbols until it replaces shell-string execution with argument-array execution, pins or vendors the Tavily search dependency, and passes only the required environment variables to child processes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-brief.mjs:82
Finding

Shell Command Injection Through User-Controlled Stock Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/generate-brief.mjs:77
Finding

Unpinned External Skill Execution With Full Environment Inheritance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README clearly states that the tool uses the Tavily API for real-time stock data, but it does not disclose that user-supplied stock symbols, company names, and related query context will be sent to a third-party service. In an investment-analysis context, those queries may reveal user interests, watchlists, or research intent, creating a privacy and data-governance risk for users who assume processing is local.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares access to an environment variable (TAVILY_API_KEY) via metadata but does not define any explicit tool scope or allowed-tools boundary. This can lead to over-broad execution context or unclear authorization expectations, increasing the chance that a hosting agent exposes secrets or code execution capability more widely than intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is a general marketing-style description of capabilities but does not specify precise trigger phrases, activation scope, or exclusion conditions. For a manifest file, this can create ambiguous or overly broad matching for when the skill should be invoked, especially around common intents like generating reports or analyzing stocks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The user-facing description and headings are entirely in Chinese, with no indication that other languages are supported or that the user can choose their preferred language. This can violate language/locale policy if the skill implicitly constrains interaction to a specific language without documenting opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language interface, help text, logs, and date formatting are fixed to Chinese, including use of the zh-CN locale and Asia/Shanghai timezone. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a stock-analysis and report-generation tool with real-time price/news retrieval, which makes network access for search expected. However, this implementation invokes execSync to spawn a child process and run an external script from the local filesystem, which is a broader capability than needed for generating investment briefs and introduces command-execution behavior not declared in the description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-controlled values such as stock name/code are interpolated into a shell command passed to execSync. Although wrapped in double quotes, shell command substitution like $(...) still executes inside double quotes, so a crafted stock name could trigger arbitrary local command execution under the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The tavilySearch function passes search terms based on user inputs to a Tavily-powered search workflow, which constitutes transmission of user-supplied data over the network. The file contains no explicit warning in the help text or generated brief that entered stock symbols/names will be sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and usage guidance are presented only in Chinese, which can amount to a language-policy issue if the skill effectively forces a specific language without opt-in or documented locale limitation. The file does not mention that the skill is China-market specific or offer alternative language support.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description says the skill supports '持仓监控' (portfolio monitoring), implying an actual monitoring/reporting capability. In code, the --portfolio path immediately reports that the feature is still under development and exits, so the described behavior is not actually provided.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate-brief.mjs:90