Back to skill

Security audit

Wealth Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is static and transparent, but it needs Review because it gives assertive financial, tax, offshore-structure, and cross-border asset-transfer guidance without enough legal and risk safeguards.

Review carefully before installing. Treat the material as educational only, not personalized investment, legal, tax, immigration, or asset-protection advice. Do not use it to evade reporting duties, capital controls, sanctions, court orders, taxes, or creditor rights; consult licensed professionals in the relevant jurisdictions before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill provides prescriptive guidance on trading returns, tax minimization, offshore trusts, asset protection, identity planning, and cross-border asset movement while presenting aggressive wealth outcomes as an operational system. Without clear warnings that this is not financial, legal, or tax advice and that legality and suitability depend on jurisdiction and licensing, users may rely on the content in ways that create serious financial loss, regulatory exposure, or unlawful tax/asset-concealment behavior.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/accumulation-calculator.html (reported line 88)May include surrounding context.

html
<div class="sub-text" id="keySub">—</div>
</div>

<!-- 裂变获客参数 -->
<div class="params-section">
  <div class="section-title">📦 裂变获客参数</div>
  <div class="controls">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/accumulation-calculator.html (reported line 183)May include surrounding context.

html
</div>
</div>

<!-- 分步计算 -->
<div class="formula-box">
  <div class="formula-title">📐 分步计算过程</div>
  <div id="steps"></div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger scope is extremely broad, covering generic topics like赚钱方法、投资策略、财富规划、风险控制、资产配置、税务筹划 and more, which can cause the skill to activate in many ordinary finance conversations. In this context, accidental invocation is risky because the skill then delivers assertive trading, offshore-asset, and tax-structure guidance without qualification, increasing the chance of inappropriate or non-jurisdiction-specific advice being surfaced to users who did not explicitly request this framework.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document gives concrete trading guidance and timing logic ('identify the end of the short move, then enter the long move') without any warning that markets are uncertain and losses can occur. In a wealth-management skill, users may reasonably treat this as actionable financial advice, increasing the chance of harmful reliance on unsupported trading claims.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section makes deterministic claims such as price '必然' moving to the other channel boundary and presenting 'high-probability' opportunities, implying guaranteed or near-guaranteed market behavior. Such certainty claims are especially dangerous in a finance-focused skill because they can mislead users into overconfidence, excessive risk-taking, and real financial loss.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly frames hedging as a mechanism to move assets across borders while offsetting gains and losses, and recommends shifting assets out of jurisdictions when regulation tightens or capital controls loom. In a wealth-management skill, this operationalizes regulatory evasion and potentially money-laundering-adjacent behavior, making the skill materially more dangerous because it offers strategic guidance for concealing or facilitating capital flight under the guise of legitimate finance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L002 sets the document language to zh-CN, and the visible UI text throughout the file is entirely Chinese. Under the stated policy, forcing a specific language/locale without user opt-in is a natural-language policy violation unless the constraint is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese from start to end. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document declares lang="zh-CN", and the visible UI text is entirely Chinese, which imposes a specific language/locale on users. Under the policy, locale constraints should either be optional for users or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.