Back to skill

Security audit

Investment Research OS

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language investment research workflow that uses public data sources and saves local reports, with no evidence of hidden persistence, credential use, account actions, or malicious behavior.

Before installing, understand that this skill can generate financial recommendations and position sizes, fetch public market data, and save research files locally. Treat outputs as research support, verify cited data independently, and do not run referenced workspace scripts unless you have inspected them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s trigger phrases are broad enough that ordinary requests like '投资分析' or '研究XXX' could invoke this skill unexpectedly. Because the skill can launch multi-step workflows, fetch external data, and write research files, overbroad activation increases the chance of unintended execution and side effects without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill specifies that outputs are stored in local files under the research directory, but the description does not warn users that their prompts and generated analysis may be persisted. This can lead to unintended retention of sensitive financial queries, internal strategy notes, or confidential company targets on disk without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

md
- Macrotrends → `https://www.macrotrends.net/stocks/charts/{TICKER}/{slug}/{metric}`
  - StockAnalysis → `https://stockanalysis.com/stocks/{TICKER}/forecast/`
  - NeoData → `neodata://{symbol}`(内部数据源)
  - OpenAlex → `https://api.openalex.org/works?filter=...`
  - World Bank → `https://api.worldbank.org/v2/country/{code}/indicator/{id}`
  - 研报/新闻 → 原文URL
- **覆盖时期**:`YYYY-MM-DD ~ YYYY-MM-DD` 或 `FY2021-FY2025`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
- StockAnalysis → `https://stockanalysis.com/stocks/{TICKER}/forecast/`
  - NeoData → `neodata://{symbol}`(内部数据源)
  - OpenAlex → `https://api.openalex.org/works?filter=...`
  - World Bank → `https://api.worldbank.org/v2/country/{code}/indicator/{id}`
  - 研报/新闻 → 原文URL
- **覆盖时期**:`YYYY-MM-DD ~ YYYY-MM-DD` 或 `FY2021-FY2025`
- **验证方式**:交叉核对(至少2个独立来源)或单来源标注 `⚠ 单来源`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill title, instructions, and required output format are all specified in Chinese, which effectively forces a specific language for user interaction and responses. Under the policy, language constraints should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is written entirely in Chinese and mandates a strict Chinese output structure, but it does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-language/regional context. This creates a natural-language policy concern because the skill effectively enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file prescribes the output format entirely in Chinese and provides no indication that the user can choose another language. This is a natural-language locale constraint that may violate language-choice policy because it imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill specification mandates Chinese-language role, headings, and output format, with no indication that the user can choose another language or locale. This is a natural-language policy concern because it imposes a specific language by default rather than offering opt-in or flexibility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill specification, required headings, and output template are written in Chinese and instruct a fixed-format Chinese report, but there is no opt-in or alternative language path for users. This creates a natural-language locale constraint that can violate organizational language-choice policies when the skill is used in broader multilingual contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file mandates a fixed output format in Chinese, including Chinese section headings and phrasing, and does not indicate that users may choose another language. This is a natural-language policy concern because it imposes a specific language/locale without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown prompt forces a specific language/locale for the skill's operation and outputs, as shown by the role, workflow, and output templates being entirely in Chinese. The policy allows locale constraints only when they are optional, user-selected, or clearly justified as region-specific; no such opt-in or justification appears here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L008 explicitly says '研究不是写报告,是形成可执行的投资判断'. Later, the same file mandates a final output titled '投资研究报告' with multiple chapters and full body content, which directly contradicts the stated principle rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest states '不写研报,只做判断', limiting the skill to judgment rather than report writing. However, this prompt instructs generation of a structured '投资研究报告' with table of contents, full正文, metadata, and report sections, which is substantively report generation rather than only a concise decision output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions, examples, and interaction phrases all assume Chinese, including the direct invocation text and CLI examples. Under the policy, forcing a specific language without opt-in or justification is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description, trigger conditions, workflow text, and usage examples are presented entirely in Chinese, and the example invocation assumes Chinese-language use. There is no statement that users may choose another language or locale, which can violate language-choice policy if the skill is not explicitly region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes the workflow and explicitly shows that output is saved to research/{公司}_{日期}.md, but it does not give the user any warning about local file creation or persistence of generated content. Because markdown files should disclose behaviors that affect user data or system state, this storage side effect should be called out more clearly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.