Back to skill

Security audit

多视角投研分析

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only stock research skill is not overtly malicious, but it overclaims implemented AI and security capabilities while requesting broad shell and file access for financial analysis.

Review this skill carefully before installing. Treat it as prompt documentation, not a working audited ML system; do not provide real brokerage credentials or sensitive datasets, avoid running unpinned install commands outside an isolated environment, and require explicit approval for network, shell, or file-write actions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:265
Finding

Unpinned third-party dependencies create a supply-chain risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:265
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

text
pip install numpy pandas scikit-learn tensorflow

Technical Analysis

The installation command does not specify package versions, integrity hashes, or an explicitly trusted package index. Package resolution can therefore change between installations. Pip installation may also execute package build hooks or other installation logic under the privileges of the invoking user.

This does not establish that the named packages are malicious. However, it creates an avoidable supply-chain exposure if an upstream release, dependency, configured package index, or resolved artifact is compromised. It also prevents reproducible security review because future installations may retrieve code different from the code originally assessed.

Attack Path

  1. A user follows the documented environment setup command.
  2. Pip resolves the latest compatible packages and transitive dependencies from the configured index.
  3. An upstream package, transitive dependency, package-index account, mirror, or artifact is compromised.
  4. Pip downloads the compromised artifact because no approved version or hash is enforced.
  5. Malicious installation logic or imported package code executes with the privileges of the user running pip.

Impact Assessment

Successful exploitation could execute arbitrary code in the installation environment. The attacker could access files, environment variables, API credentials, network resources, and application data available to the invoking account. If installation is performed with elevated privileges, the impact could extend to system-wide files and configuration. The exact scope remains constrained by the operating-system account, container, sandbox, and network controls in effect.

Remediation
View remediation

Remediation Suggestions

  1. Replace the ad hoc installation command with a reviewed lock file containing exact direct and transitive dependency versions.
  2. Require artifact hashes, such as by using pip install --require-hashes -r requirements.txt.
  3. Configure an explicit, trusted package index or an internally controlled artifact repository.
  4. Scan locked dependencies for known vulnerabilities and review updates before changing the lock file.
  5. Install dependencies inside an isolated virtual environment or container as an unprivileged user.
  6. Separate heavyweight optional dependencies from the minimum runtime requirements.
  7. Document the source and reviewed version of the referenced multi_research module before instructing users to import or install it.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:9
Finding

Skill requests shell and filesystem modification capabilities beyond demonstrated requirements

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-13
Vulnerability Type: Excessive agent tool permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - Read
  - Write
  - Edit
  - Bash

Technical Analysis

The Skill declares general-purpose read, write, edit, and shell-execution capabilities. The audited package contains only this Markdown instruction file and does not include an implementation that establishes why unrestricted command execution or arbitrary file modification is necessary for stock analysis.

Bash, Write, and Edit materially expand the consequences of malicious input, model error, or unsafe operational guidance. A stock-analysis workflow generally needs access to explicitly selected input data, approved external data sources, and a designated output location—not unrestricted shell and filesystem access.

Tool availability alone does not prove that commands will be executed maliciously. The security issue is the violation of least privilege: if adversarial content influences the agent into making an unsafe tool call, the declared capabilities provide a path to host-level actions that the documented analysis task does not require.

Attack Path

  1. The Skill is loaded with all declared tools enabled.
  2. The agent processes attacker-controlled content from a user request, stock dataset, news article, social-media record, or other external analysis input.
  3. The content induces or contributes to an unsafe instruction, command, or file operation.
  4. The agent invokes Bash, Write, or Edit under the authority granted to the Skill.
  5. Files accessible to the agent are modified, commands are executed, or sensitive local data is read and potentially included in generated output or network-bound processing.

Impact Assessment

The available scope includes command execution and the ability to read or modify files accessible to the agent process. Depending o ...[truncated 469 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove Bash, Write, and Edit unless a specific implemented operation requires each capability.
  2. Prefer a dedicated market-data API tool over a general-purpose shell.
  3. Restrict Read to user-selected input files and approved dataset directories.
  4. If report export is required, replace unrestricted write access with a tool limited to a designated output directory and safe file types.
  5. Require explicit user confirmation before executing commands, installing dependencies, overwriting files, or accessing paths outside the active workspace.
  6. Run the Skill as an unprivileged account inside a sandbox with filesystem and network allowlists.
  7. Treat external news, social-media content, datasets, and retrieved documents as untrusted data rather than executable instructions.
  8. Document every retained tool, its legitimate purpose, allowed arguments, permitted paths, and failure behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes advanced ML, deep learning, Bayesian modeling, training, deployment, and prediction as if they are present, but the package is only Markdown instructions with no implementation. Such overstated capability can cause users to rely on fabricated analysis quality, and in a financial context that can drive unsafe decisions or prompt unnecessary privileged operations to 'support' nonexistent features.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that key security controls are 'implemented,' but this artifact is only instructional Markdown and contains no mechanism to enforce encryption, key rotation, access control, input validation, or vulnerability scanning. This creates a false assurance problem: users or agents may assume protections exist and expose secrets or run the skill in more privileged contexts than is safe.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill claims that risky code was removed and safety/stability were improved, yet the same document advertises Bash, external network access, API keys, and file read/write capabilities. In a Markdown-only skill, such claims can mislead users or downstream agents into trusting the skill more than warranted and may reduce scrutiny before sensitive operations are performed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill whenever '用户需要多视角投研分析相关功能时使用', which is a broad natural-language trigger without specific invocation phrases, scope limits, or negative examples. This ambiguity increases the chance of unintended activation for loosely related finance or analysis requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase '本技能提供相关功能时使用' does not clearly distinguish when the skill should be invoked versus when it should not. It lacks concrete trigger wording or contextual constraints, making activation criteria unclear.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill declares dependence on external services, API keys, filesystem access, and command-line tooling, yet it does not prominently warn users that using the skill may access networks, handle secrets, or perform local system operations. In an agent setting, missing consent and disclosure materially increases the chance of unintended data exposure or unauthorized actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.