Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
声明描述聚焦于A股指数行情相关能力,包括指数详情、列表、K线和分时;而代码仅提供“前N个交易日”的日期查询功能。虽然同属 market.ft.tech 域下的市场数据场景,但该功能与指数行情查询并不等价,也不属于声明中列出的任一能力。该代码的主要目的与声明的技能用途存在实质性偏差,因此应判定为描述与行为不匹配。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed China A-share index data helper that calls documented market.ft.tech read-only endpoints.
Install only if you are comfortable with a skill that runs bundled Python handlers and sends requested A-share index symbols, filters, dates, and pagination parameters to market.ft.tech. It appears read-only and purpose-aligned, but its interface is primarily Chinese and depends on that external market-data service.
声明描述聚焦于A股指数行情相关能力,包括指数详情、列表、K线和分时;而代码仅提供“前N个交易日”的日期查询功能。虽然同属 market.ft.tech 域下的市场数据场景,但该功能与指数行情查询并不等价,也不属于声明中列出的任一能力。该代码的主要目的与声明的技能用途存在实质性偏差,因此应判定为描述与行为不匹配。
Referenced artifact was not completely inspected
`run.py` 与本文件(`SKILL.md`)位于同一目录。执行时:
The skill instructs the agent to derive and execute a local run.py, and explicitly describes outbound HTTP access to https://market.ft.tech, but it declares no permissions or allowed-tools scope. That creates an under-scoped, over-capable skill where file access, shell execution, and network use are implicit rather than constrained, increasing the chance of unintended command execution or data exfiltration if the runtime grants broad defaults.
The '询问方式' table uses broad phrases such as '有哪些指数', '指数列表', and '近 N 天交易日' as activation cues without clear exclusion conditions. These overlap with ordinary finance-related conversation and do not specify when this skill should activate versus other market-data skills, increasing the chance of unintended invocation.
The manifest describes the skill as covering index details, paginated index lists, index K-line data, and minute-level intraday prices. The module documentation includes get-nth-trade-date as a supported subskill, which is a trading-calendar/date utility rather than index data retrieval, indicating the skill exposes behavior beyond the stated manifest scope.
This Python file contains multiple user-facing natural-language strings in Chinese, including the module docstring, CLI description, argument help, and error output. Because the skill does not provide any language/locale opt-in or indicate that it is intentionally restricted to Chinese users, it violates the language/locale policy criteria.
The trigger description includes very broad terms such as 指数行情 and 成交, which can match a wide range of index-related requests beyond a single-index detail lookup. This can cause the wrong skill to be selected, leading to overbroad data retrieval, incorrect routing, or misleading answers when the user actually needs a list, K-line, or intraday function.
The natural-language description and title are entirely Chinese and frame usage around Chinese query forms, but they do not explicitly state that the skill is limited to Chinese-language or China-market contexts as an intentional locale constraint. Under the policy, forcing a specific language without user opt-in or documented justification is a violation.
The manifest description and document content are written entirely in Chinese, which effectively imposes a specific language on users. The file does not offer an opt-in choice of language or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
This code file contains user-facing natural-language strings such as the module docstring and argparse descriptions exclusively in Chinese. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The natural-language description is entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the language/locale policy, forcing a specific language without opt-in is a policy concern unless the locale restriction is clearly documented and justified.
The natural-language strings in the module docstring and CLI help are entirely in Chinese, which effectively imposes a single language/locale on users without opt-in or explanation. The policy requires flagging language or locale constraints when the skill does not offer a choice or clearly justify a region-specific limitation.
The manifest description and the entire markdown content are written only in Chinese, and the skill text provides no indication that language is optional or region-justified. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The module docstring and CLI description are written entirely in Chinese, indicating a fixed language/locale expectation. Under the policy, forcing a specific language without offering user choice or documenting a justified regional constraint is a natural-language policy violation.
This file contains natural-language usage guidance exclusively in Chinese, and later user-facing runtime messages are also Chinese-only. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.
The script prints usage and error messages only in Chinese, which forces a specific language for interactive output. The policy allows locale constraints only when they are optional or clearly documented and justified.
The natural-language description is written entirely in Chinese and assumes Chinese query phrasing such as “前 N 个交易日” and “近 N 天”, with no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without opt-in can be a locale-policy issue unless the regional constraint is explicitly documented and justified.
This Python code issues an external HTTP GET request to market.ft.tech using user-supplied parameters, but the file contains no comment, docstring detail, or explicit user-facing notice that input values will be sent to a remote service. For code files, outbound network calls that transmit user or system data should have some visible disclosure unless the warning is clearly documented elsewhere.
No suspicious patterns detected.