Back to skill

Security audit

金融素养学习工具

Security checks across malware telemetry and agentic risk

Overview

This financial-literacy skill is mostly a text knowledge guide, but it asks for command execution and file-reading authority while also advertising broader automation, file, and API capabilities that do not fit its stated purpose.

Review this skill before installing. Its financial education content is not itself harmful, and no exfiltration or destructive instructions were found, but the requested exec/read authority and generic automation/API/file claims are broader than a basic learning tool needs. Install only if you are comfortable with those permissions or after the publisher narrows the manifest and removes unrelated automation language.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The document explicitly presents the skill as a pure markdown knowledge-base tool with no external data calls, but later advertises API integration, file handling, and command execution. This contradiction can mislead users and policy layers into granting trust or permissions inappropriate for the actual capability set, increasing the chance of unexpected code or network actions.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest and top-level description frame the skill as a basic financial-literacy educator, but the body expands it into a generic automation skill with command execution, file processing, and API integration. That mismatch enables privilege laundering: a seemingly harmless skill may be approved or invoked in contexts where such capabilities would otherwise be blocked or scrutinized.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
System command execution is not needed for a static financial education knowledge tool, yet the skill advertises command execution and is granted exec. Unnecessary execution capability materially raises risk of host inspection, arbitrary command abuse, or chaining with user prompts to perform actions outside the stated educational scope.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
File processing, especially write support, is unjustified for a financial-literacy primer and expands the skill's ability to access or modify local data. Even if not currently wired, documenting or implying such capability can cause over-permissioning and opens paths to data exposure or tampering if implemented later.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
Advertising external API integration directly contradicts the claim that the free version uses only a local knowledge base and no external data calls. Hidden or unjustified network capability can expose user queries externally, bypass user expectations, and broaden the attack surface through remote services.

Vague Triggers

High
Confidence
90% confidence
Finding
The invocation text is overly broad and can cause the skill to match requests beyond financial literacy. Over-broad triggering is dangerous here because the skill carries privileged tools, so accidental activation could expose exec/read capabilities in unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The scope section includes vague and unrelated keywords such as data analysis, report generation, statistics, visualization, and workflow use, which greatly expands possible triggering. In combination with read/exec permissions, ambiguous trigger boundaries increase the risk of the skill being invoked as a general-purpose automation wrapper under an innocuous finance label.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.