Back to skill

Security audit

舆情情绪分析免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a stock-news sentiment guide that asks for network-backed data collection and command execution in a disclosed, purpose-aligned way, with no evidence of hidden persistence, credential theft, destructive actions, or exfiltration.

Install only if you are comfortable with an agent running a local Python-based workflow and contacting external finance, news, and social-media sources for the stock symbols you provide. Because the referenced script is not present in this artifact, review any script supplied later before running it, especially if you add paid data-source API keys.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition is extremely broad ('需要数据分析、报表生成、统计洞察、数据可视化时使用'), which can cause the agent to invoke this skill for many unrelated requests. Because the skill has network-oriented functionality and declares the exec tool, over-triggering increases the chance of unnecessary external data collection or command execution in contexts the user did not intend.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes collecting data from external news, finance, and social-media sources, but it does not present a clear upfront warning that using the skill may contact third-party services and transmit user-supplied stock symbols or query context externally. This reduces informed consent and can surprise users in privacy-sensitive or restricted-network environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.