Back to skill

Security audit

专业财务分析助手

Security checks for vulnerabilities and agentic risk

Overview

This finance skill should be reviewed before installation because some valuation and risk commands present fixed sample numbers as stock-specific analysis.

Install only if you understand that parts of the valuation and risk output appear to be examples, not real stock-specific analysis. Do not rely on its buy/risk conclusions for financial decisions unless the publisher replaces the fixed outputs with validated live calculations, pins dependencies consistently, and clearly labels educational or sample content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unbounded and Inconsistent Third-Party Dependency Resolution

Content
View full analysis
=1.2.89", "pandas>=1.5", "numpy>=1.24"] install: - id: pip-install kind: pip packages: ["tushare>=1.2.89", "pandas>=1.5", "numpy>=1.24"] ``` The package metadata separately declares different versions: ```json "dependencies": { "tushare": "1.2.88", "pandas": "1.5.3", "numpy": "1.23.5" } ``` ### Technical Analysis The installation instructions use lower-bound constraints without upper bounds, hashes, or a lock file. Consequently, an installation can resolve dependency versions that were released after this Skill was reviewed. Those releases may contain compromised installation hooks, malicious import-time behavior, or incompatible functionality. The declarations are also inconsistent. `SKILL.md` requires versions newer than or equal to `tushare 1.2.89`, `pandas 1.5`, and `numpy 1.24`, while `package.json` lists `tushare 1.2.88`, `pandas 1.5.3`, and `numpy 1.23.5`. Therefore, the exact dependency set used at runtime depends on which installer or metadata source takes precedence. This does not establish that the currently named packages are malicious. The vulnerability is that future or otherwise unreviewed releases can enter the trusted execution path without integrity verification. ### Attack Path 1. An attacker compromises a permitted dependency release or its package-publishing account. 2. The attacker publishes a version satisfying one of the open-ended constraints. 3. A user or automated Skill installer resolves the newly published version. 4. The package executes attacker-controlled behavior during installation or when imported. 5. That behavior runs with the permissions of the user or service installing or invoking the Skill. ### Impact Assessment Successful ...[truncated 411 chars]
Remediation
View remediation

other

Error
Location
scripts/finance_analysis.py:123
Finding

Stock-Specific Valuation and Risk Commands Return Fabricated Fixed Results

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill description, usage guidance, and marketing copy are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. The policy requires language or locale constraints to be opt-in or clearly justified; this file does neither.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill accesses environment-based secrets via TUSHARE_TOKEN and clearly relies on env capabilities, but it does not declare any tool scope, permissions, or allowed-tools boundary. This creates an implicit privilege surface: an agent/runtime may grant broader environment access than users expect, increasing the risk of unintended secret exposure or unauthorized use of host credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is written entirely in Chinese, and the rest of the skill content, labels, examples, and returned strings consistently assume Chinese output. There is no user opt-in, alternative language option, or documented region-specific justification, which makes this a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill advertises 自动投资建议 and 定期分析推送, which imply potentially consequential automated guidance and ongoing user-affecting behavior, yet the documentation does not clearly explain data handling, consent, scheduling behavior, or notification/push mechanics. In a finance context, opaque automation increases the risk of privacy issues, surprise background actions, and overreliance on unqualified recommendations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code’s natural-language interface and documentation are presented exclusively in Chinese, beginning with the module description and authoring text. The file does not indicate that language selection is optional or limited to a justified region-specific use case, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The DCF valuation function claims to analyze a user-specified stock but actually emits hard-coded example assumptions and outputs that are unrelated to the input. In a finance-analysis skill, this is dangerous because users may rely on fabricated valuation results for real investment decisions, creating a material integrity and safety risk even though it is not a code-execution issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The relative valuation function presents company multiples, industry averages, and a buy/wait recommendation, but all values are fixed and do not use the supplied stock code. In the context of an investment assistant, this can mislead users into believing security-specific valuation work was performed when it was not, potentially causing harmful financial decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The risk assessment function outputs fixed liquidity, leverage, growth, and overall risk scores regardless of the target stock. Because this skill is explicitly positioned as professional financial analysis, presenting static low-risk conclusions as if they were real assessments can dangerously misinform users about investment risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command descriptions, examples, argument help text, and runtime messages are all hard-coded in Chinese, making the skill effectively require a specific language for operation. There is no mechanism for the user to choose another language and no documented justification for a Chinese-only locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script emits explicit investment advice such as '可以买入', '值得买入', and '强烈买入' based on simplistic heuristics, without any disclaimer that the output is informational, not personalized financial advice, and may be incomplete or wrong. In a finance-analysis skill, this is more dangerous because users are likely to rely on the output for real trading decisions, creating risk of financial harm and compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description is written only in Chinese, which can imply a fixed language expectation for the skill without any stated user opt-in or locale limitation. Under the language/locale policy check, this is a natural-language metadata choice that may exclude users unless the skill explicitly documents that it is Chinese-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings throughout the file, including the module description and all CLI output, are in Chinese only. The policy requires avoiding forced language or locale constraints unless the skill offers user choice or clearly documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.