Back to skill

Security audit

xqant daily gushouplus report

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its financial-report purpose, but it documents persistent every-minute automated execution and chat posting that is broader than a daily 21:30 report.

Review before installing. Confirm whether the cron job actually exists and disable or rescope it unless you intentionally want automatic runs every 60 seconds with chat posting. Use only with authorized Wind access, monitor API quota/cost, and verify the referenced product lists before relying on the generated financial report.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and loosely bounded, such as generic requests for product performance or '87 products data', which can cause the skill to activate outside its intended operational context. In this skill, unintended activation is more concerning because execution initiates large-scale external data queries, attribution analysis, and potentially scheduled or repeated processing, increasing the chance of unnecessary data access, cost, or operational misuse.

Static analysis

No suspicious patterns detected.