Back to skill

Security audit

深蓝企业情报

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent public API helper for company intelligence and does not request credentials, persistence, installs, or local data access.

Install this only if you are comfortable with an agent making public HTTPS requests to shenlannews.com for company, announcement, sentiment, and follower-attention data. Treat outputs as informational business intelligence, not financial advice, and avoid sending private or sensitive company research through the external API unless you trust that provider.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The code exposes a company follower-list endpoint even though the stated skill scope only mentions company profiles, public opinion tracking, announcements, and trending companies. This creates a scope mismatch that can lead to unintended access to relationship or audience data, increasing privacy and data-governance risk if the agent is allowed to invoke capabilities users and operators did not expect.

Static analysis

No suspicious patterns detected.