Back to skill

Security audit

财经资讯助手免费版

Security checks across malware telemetry and agentic risk

Overview

This is a finance-news summarization skill with some overly broad and sloppy wording, but no inspected artifact shows hidden, destructive, credential-seeking, or exfiltrating behavior.

Install only if you are comfortable letting the agent search current financial news and optionally use simple shell commands for local preference or output files. Treat generated market analysis as informational, not investment advice, and ask the agent to confirm before creating, importing, exporting, modifying, or resetting any local files or configuration.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Confidence
87% confidence
Finding
The trigger guidance is overly broad and can cause the skill to activate for generic requests involving AI, dialogue, or agent orchestration rather than clearly bounded finance-news tasks. In a tool with exec capability and references to create/query/export behavior, ambiguous activation increases the chance of unintended invocation and downstream actions outside the user's informed intent.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The example activation phrase uses everyday language that is broad enough to match many normal conversations without clarifying scope, data sources, or operational limits. While not directly malicious, this can lead to over-triggering and unintended use of the skill, especially when combined with agent autonomy and access to tools such as exec.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises create/query/export and modify/reset/import operations via input_params and config_options without clearly warning that these may change local files or configuration. Because the skill also declares exec/read/glob/grep tools and later includes filesystem examples, a user could unknowingly authorize local state changes, exports, or imports that affect their environment.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.