Back to skill

Security audit

深蓝AI分析师

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Shenlan finance API client that fetches public financial analysis and TTS data, with no evidence of hidden credential use, persistence, or destructive behavior.

Install only if you are comfortable with finance queries being answered using Shenlan's external API and AI-generated analysis. Avoid sending private or sensitive financial documents or personal trading details, and treat the results as informational rather than investment advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description uses broad finance-analysis phrasing like '当用户需要对财经内容进行AI分析' and related generic scenarios, which can cause the skill to activate for a wide range of loosely related requests. Over-broad activation increases the chance that sensitive user content or financial queries are routed to an external third-party API without clear necessity or consent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The usage guidance includes generic triggers such as '市场情绪怎么样' and '某某股票的舆情分析,' which are broad enough to capture many ordinary finance questions. In context, this is more dangerous because the skill is wired to external APIs and could steer general user requests into third-party processing or authoritative-sounding analysis without clear boundaries.

Static analysis

No suspicious patterns detected.