Back to skill

Security audit

Daily Portfolio Analysis

Security checks for vulnerabilities and agentic risk

Overview

This portfolio skill is coherent, but it should be reviewed because it can automatically send sensitive holdings reports to Feishu without clear per-run consent or visible destination controls.

Install only if you are comfortable storing real portfolio data under the OpenClaw workspace and sending complete reports through the configured Feishu notifier. Before using it, verify the Feishu destination, redact brokerage screenshots and account identifiers, and prefer adding a local-only or confirmation step before any push delivery.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior does not fully disclose sensitive operations: local persistence of portfolio data, cache files, and outbound delivery to Feishu/WeChat. For a skill processing real holdings and screenshots, this mismatch is dangerous because users may provide confidential brokerage data without understanding it will be stored and potentially sent externally.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises functionality that clearly implies file access, local persistence, and network access, but it does not declare any explicit tool scope or permissions. In a portfolio-analysis skill handling sensitive financial holdings, missing least-privilege boundaries increases the chance of overbroad access, unintended data reads/writes, and unnoticed outbound transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that reports can be automatically pushed to Feishu/WeChat but does not warn that highly sensitive portfolio composition and valuation data may be sent to third-party messaging platforms. Automated external transmission increases the risk of disclosure to the wrong recipient, insecure chat environments, or organizational logging systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill encourages users to upload brokerage screenshots so it can generate a portfolio configuration file, but it provides no clear privacy notice about processing, retention, redaction, or secondary use of that sensitive financial data. Screenshots may contain account identifiers, balances, and holdings, making this a significant confidentiality risk if mishandled or stored insecurely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad everyday requests such as asking for a portfolio report or how holdings look today, which can be invoked unintentionally in normal conversation. Because the skill may access sensitive financial data and send reports, accidental activation could expose portfolio information or trigger unwanted outbound actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language strings in the template are entirely in Chinese, including core instructions and privacy guidance, with no indication that the skill supports other languages or that Chinese is a required regional constraint. This can violate language/locale policy when users are not given an explicit language choice or opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script captures a full portfolio analysis report and automatically sends it to Feishu on execution, which is an external disclosure of sensitive financial data. Because the file itself provides no consent check, destination validation, or redaction, running the script can leak holdings, valuations, and daily P/L to a third-party messaging channel unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Sending the portfolio summary to Feishu without any user-facing warning or confirmation is a privacy and data exfiltration risk, especially since the generated report contains consolidated account information and market values. In the context of a finance skill, silent outbound messaging materially increases the danger because the data is highly sensitive and actionable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

描述全文以中文直接规定技能用途与交互方式,且未说明是否支持其他语言或允许用户选择语言。按照语言/locale 政策,若技能限制特定语言,应提供用户选择或清晰说明这是特定区域场景下的合理约束。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and multiple user-facing strings are fixed in Chinese, which imposes a specific language without offering user choice. The policy requires avoiding forced language or locale unless the constraint is explicitly justified or opt-in is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.