Back to skill

Security audit

金融素养专业版

Security checks across malware telemetry and agentic risk

Overview

This finance-training skill is not clearly malicious, but it asks for broad execution/write authority and handles sensitive financial and employee data with inconsistent privacy and API claims.

Review before installing. Use this only with non-sensitive or minimized financial and employee data unless you are comfortable with local storage and possible LLM/API/network processing. Avoid installing the referenced pip package until you can verify its publisher and contents, and do not allow arbitrary command execution outside the documented finance workflows.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The document tells users that all financial calculations, training content, and learning data are handled locally, but elsewhere it declares LLM/API dependence and mentions network-related failure handling. That inconsistency can mislead users into sharing sensitive financial or employee data under false privacy assumptions, increasing the chance of unintended external transmission.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The skill advertises generic command execution despite being framed as a financial education and planning tool. Unnecessary execution capability materially expands the attack surface: if later combined with user-controlled inputs or prompt-driven behavior, the agent could run unrelated system commands, access local files, or pivot beyond the intended domain.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The skill claims external API integration even though its stated purpose is local financial education/planning and it separately claims local-only processing. This mismatch broadens the data-exposure surface and may cause users to provide sensitive information without understanding that third-party services could be contacted.

Vague Triggers

High
Confidence
89% confidence
Finding
The description includes unrelated trigger guidance about project management, task planning, progress tracking, and team collaboration, which is far broader than the declared finance-focused scope. Overbroad invocation cues can cause the agent to activate this skill in inappropriate contexts, exposing exec/write/network-capable functionality when users did not intend to use a finance tool.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The capability coverage section lists broad, fragmented everyday keywords as activation cues without meaningful scope limits. In an agent environment, that can lead to accidental or excessive routing of user requests into a skill with read/write/exec capabilities, increasing the chance of unintended data handling or command execution.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill discusses local storage, progress tracking, reports, and handling of personal financial and employee training information, but does not provide a prominent warning about the sensitivity of that data or the risks of writing it to disk. Users may unknowingly persist highly sensitive information in local databases or PDF reports that are accessible to other users, backups, or endpoint tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.